Answer in brief
CVE-2025-38193 records a Unknown severity vulnerability in net_sched: sch_sfq: reject invalid perturb period. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38193 records a Unknown severity vulnerability in net_sched: sch_sfq: reject invalid perturb period. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e0936ff56be4e08ad5b60ec26971eae0c40af305 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2254d038dab9c194fe6a4b1ce31034f42e91a6e5 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <956b5aebb349449b38d920d444ca1392d43719d1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b11a50544af691b787384089b68f740ae20a441b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <0357da9149eac621f39e235a135ebf155f01f7c3 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f9b97d466e6026ccbdda30bb5b71965b67ccbc82 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <590b2d7d0beadba2aa576708a05a05f0aae39295 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7ca52541c05c832d32b112274f81a985101f9ba8 | e0936ff56be4e08ad5b60ec26971eae0c40af305, 2254d038dab9c194fe6a4b1ce31034f42e91a6e5, 956b5aebb349449b38d920d444ca1392d43719d1, b11a50544af691b787384089b68f740ae20a441b, 0357da9149eac621f39e235a135ebf155f01f7c3, f9b97d466e6026ccbdda30bb5b71965b67ccbc82, 590b2d7d0beadba2aa576708a05a05f0aae39295, 7ca52541c05c832d32b112274f81a985101f9ba8 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Jul 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb_period * HZ will not overflow and is positive. tc qd add dev lo root sfq perturb -10 # negative value : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 1000000000 # too big : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 2000000 # acceptable value tc -s -d qd sh dev lo qdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) backlog 0b 0p requeues 0
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e0936ff56be4e08ad5b60ec26971eae0c40af305 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <2254d038dab9c194fe6a4b1ce31034f42e91a6e5 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <956b5aebb349449b38d920d444ca1392d43719d1 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <b11a50544af691b787384089b68f740ae20a441b || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <0357da9149eac621f39e235a135ebf155f01f7c3 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <f9b97d466e6026ccbdda30bb5b71965b67ccbc82 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <590b2d7d0beadba2aa576708a05a05f0aae39295 || >=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7ca52541c05c832d32b112274f81a985101f9ba8 | e0936ff56be4e08ad5b60ec26971eae0c40af305, 2254d038dab9c194fe6a4b1ce31034f42e91a6e5, 956b5aebb349449b38d920d444ca1392d43719d1, b11a50544af691b787384089b68f740ae20a441b, 0357da9149eac621f39e235a135ebf155f01f7c3, f9b97d466e6026ccbdda30bb5b71965b67ccbc82, 590b2d7d0beadba2aa576708a05a05f0aae39295, 7ca52541c05c832d32b112274f81a985101f9ba8 |
| Linux/Linuxgeneric | 2.6.12 | Not reported |
Published upstream
Jul 4, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net_sched: sch_sfq: reject invalid perturb period Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb_period * HZ will not overflow and is positive. tc qd add dev lo root sfq perturb -10 # negative value : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 1000000000 # too big : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 2000000 # acceptable value tc -s -d qd sh dev lo qdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) backlog 0b 0p requeues 0
Quoted source text, attributed separately from HOL analysis.