Answer in brief
CVE-2025-21971 records a Unknown severity vulnerability in net_sched: Prevent creation of classes with TC_H_ROOT. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21971 records a Unknown severity vulnerability in net_sched: Prevent creation of classes with TC_H_ROOT. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=066a3b5b2346febf9a655b444567b7138e3bb939 <e05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4c || >=066a3b5b2346febf9a655b444567b7138e3bb939 <7a82fe67a9f4d7123d8e5ba8f0f0806c28695006 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <003d92c91cdb5a64b25a9a74cb8543aac9a8bb48 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <78533c4a29ac3aeddce4b481770beaaa4f3bfb67 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <94edfdfb9505ab608e86599d1d1e38c83816fc1c || >=066a3b5b2346febf9a655b444567b7138e3bb939 <0c3057a5a04d07120b3d0ec9c79568fceb9c921e | e05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4c, 7a82fe67a9f4d7123d8e5ba8f0f0806c28695006, 003d92c91cdb5a64b25a9a74cb8543aac9a8bb48, e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7, 78533c4a29ac3aeddce4b481770beaaa4f3bfb67, 5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7, 94edfdfb9505ab608e86599d1d1e38c83816fc1c, 0c3057a5a04d07120b3d0ec9c79568fceb9c921e |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_ROOT The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination condition when traversing up the qdisc tree to update parent backlog counters. However, if a class is created with classid TC_H_ROOT, the traversal terminates prematurely at this class instead of reaching the actual root qdisc, causing parent statistics to be incorrectly maintained. In case of DRR, this could lead to a crash as reported by Mingi Cho. Prevent the creation of any Qdisc class with classid TC_H_ROOT (0xFFFFFFFF) across all qdisc types, as suggested by Jamal.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=066a3b5b2346febf9a655b444567b7138e3bb939 <e05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4c || >=066a3b5b2346febf9a655b444567b7138e3bb939 <7a82fe67a9f4d7123d8e5ba8f0f0806c28695006 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <003d92c91cdb5a64b25a9a74cb8543aac9a8bb48 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <78533c4a29ac3aeddce4b481770beaaa4f3bfb67 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7 || >=066a3b5b2346febf9a655b444567b7138e3bb939 <94edfdfb9505ab608e86599d1d1e38c83816fc1c || >=066a3b5b2346febf9a655b444567b7138e3bb939 <0c3057a5a04d07120b3d0ec9c79568fceb9c921e | e05d9938b1b0ac40b6054cc5fa0ccbd9afd5ed4c, 7a82fe67a9f4d7123d8e5ba8f0f0806c28695006, 003d92c91cdb5a64b25a9a74cb8543aac9a8bb48, e5ee00607bbfc97ef1526ea95b6b2458ac9e7cb7, 78533c4a29ac3aeddce4b481770beaaa4f3bfb67, 5c3ca9cb48b51bd72bf76b8b05e24f3cd53db5e7, 94edfdfb9505ab608e86599d1d1e38c83816fc1c, 0c3057a5a04d07120b3d0ec9c79568fceb9c921e |
| Linux/Linuxgeneric | 2.6.25 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: Prevent creation of classes with TC_H_ROOT The function qdisc_tree_reduce_backlog() uses TC_H_ROOT as a termination condition when traversing up the qdisc tree to update parent backlog counters. However, if a class is created with classid TC_H_ROOT, the traversal terminates prematurely at this class instead of reaching the actual root qdisc, causing parent statistics to be incorrectly maintained. In case of DRR, this could lead to a crash as reported by Mingi Cho. Prevent the creation of any Qdisc class with classid TC_H_ROOT (0xFFFFFFFF) across all qdisc types, as suggested by Jamal.
Quoted source text, attributed separately from HOL analysis.