Answer in brief
CVE-2025-38115 records a Unknown severity vulnerability in net_sched: sch_sfq: fix a potential crash on gso_skb handling. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38115 records a Unknown severity vulnerability in net_sched: sch_sfq: fix a potential crash on gso_skb handling. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <c337efb20d6d9f9bbb4746f6b119917af5c886dc || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <b44f791f27b14c9eb6b907fbe51f2ba8bec32085 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <5814a7fc3abb41f63f2d44c9d3ff9d4e62965b72 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <9c19498bdd7cb9d854bd3c54260f71cf7408495e || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <b4e9bab6011b9559b7c157b16b91ae46d4d8c533 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <d1bc80da75c789f2f6830df89d91fb2f7a509943 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <82448d4dcd8406dec688632a405fdcf7f170ec69 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <82ffbe7776d0ac084031f114167712269bf3d832 | c337efb20d6d9f9bbb4746f6b119917af5c886dc, b44f791f27b14c9eb6b907fbe51f2ba8bec32085, 5814a7fc3abb41f63f2d44c9d3ff9d4e62965b72, 9c19498bdd7cb9d854bd3c54260f71cf7408495e, b4e9bab6011b9559b7c157b16b91ae46d4d8c533, d1bc80da75c789f2f6830df89d91fb2f7a509943, 82448d4dcd8406dec688632a405fdcf7f170ec69, 82ffbe7776d0ac084031f114167712269bf3d832 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Jul 3, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: fix a potential crash on gso_skb handling SFQ has an assumption of always being able to queue at least one packet. However, after the blamed commit, sch->q.len can be inflated by packets in sch->gso_skb, and an enqueue() on an empty SFQ qdisc can be followed by an immediate drop. Fix sfq_drop() to properly clear q->tail in this situation. ip netns add lb ip link add dev to-lb type veth peer name in-lb netns lb ethtool -K to-lb tso off # force qdisc to requeue gso_skb ip netns exec lb ethtool -K in-lb gro on # enable NAPI ip link set dev to-lb up ip -netns lb link set dev in-lb up ip addr add dev to-lb 192.168.20.1/24 ip -netns lb addr add dev in-lb 192.168.20.2/24 tc qdisc replace dev to-lb root sfq limit 100 ip netns exec lb netserver netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 &
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <c337efb20d6d9f9bbb4746f6b119917af5c886dc || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <b44f791f27b14c9eb6b907fbe51f2ba8bec32085 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <5814a7fc3abb41f63f2d44c9d3ff9d4e62965b72 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <9c19498bdd7cb9d854bd3c54260f71cf7408495e || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <b4e9bab6011b9559b7c157b16b91ae46d4d8c533 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <d1bc80da75c789f2f6830df89d91fb2f7a509943 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <82448d4dcd8406dec688632a405fdcf7f170ec69 || >=a53851e2c3218aa30b77abd6e68cf1c371f15afe <82ffbe7776d0ac084031f114167712269bf3d832 | c337efb20d6d9f9bbb4746f6b119917af5c886dc, b44f791f27b14c9eb6b907fbe51f2ba8bec32085, 5814a7fc3abb41f63f2d44c9d3ff9d4e62965b72, 9c19498bdd7cb9d854bd3c54260f71cf7408495e, b4e9bab6011b9559b7c157b16b91ae46d4d8c533, d1bc80da75c789f2f6830df89d91fb2f7a509943, 82448d4dcd8406dec688632a405fdcf7f170ec69, 82ffbe7776d0ac084031f114167712269bf3d832 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Jul 3, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: fix a potential crash on gso_skb handling SFQ has an assumption of always being able to queue at least one packet. However, after the blamed commit, sch->q.len can be inflated by packets in sch->gso_skb, and an enqueue() on an empty SFQ qdisc can be followed by an immediate drop. Fix sfq_drop() to properly clear q->tail in this situation. ip netns add lb ip link add dev to-lb type veth peer name in-lb netns lb ethtool -K to-lb tso off # force qdisc to requeue gso_skb ip netns exec lb ethtool -K in-lb gro on # enable NAPI ip link set dev to-lb up ip -netns lb link set dev in-lb up ip addr add dev to-lb 192.168.20.1/24 ip -netns lb addr add dev in-lb 192.168.20.2/24 tc qdisc replace dev to-lb root sfq limit 100 ip netns exec lb netserver netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 & netperf -H 192.168.20.2 -l 100 &
Quoted source text, attributed separately from HOL analysis.