Answer in brief
CVE-2025-38477 records a Unknown severity vulnerability in net/sched: sch_qfq: Fix race condition on qfq_aggregate. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=462dbc9101acd38e92eda93c0726857517a24bbd <aa7a22c4d678bf649fd3a1d27debec583563414d || >=462dbc9101acd38e92eda93c0726857517a24bbd <d841aa5518508ab195b6781ad0d73ee378d713dd || >=462dbc9101acd38e92eda93c0726857517a24bbd <c6df794000147a3a02f79984aada4ce83f8d0a1e || >=462dbc9101acd38e92eda93c0726857517a24bbd <466e10194ab81caa2ee6a332d33ba16bcceeeba6 || >=462dbc9101acd38e92eda93c0726857517a24bbd <fbe48f06e64134dfeafa89ad23387f66ebca3527 || >=462dbc9101acd38e92eda93c0726857517a24bbd <a6d735100f602c830c16d69fb6d780eebd8c9ae1 || >=462dbc9101acd38e92eda93c0726857517a24bbd <c000a3a330d97f6c073ace5aa5faf94b9adb4b79 || >=462dbc9101acd38e92eda93c0726857517a24bbd <5e28d5a3f774f118896aec17a3a20a9c5c9dfc64 | aa7a22c4d678bf649fd3a1d27debec583563414d, d841aa5518508ab195b6781ad0d73ee378d713dd, c6df794000147a3a02f79984aada4ce83f8d0a1e, 466e10194ab81caa2ee6a332d33ba16bcceeeba6, fbe48f06e64134dfeafa89ad23387f66ebca3527, a6d735100f602c830c16d69fb6d780eebd8c9ae1, c000a3a330d97f6c073ace5aa5faf94b9adb4b79, 5e28d5a3f774f118896aec17a3a20a9c5c9dfc64 |
| Linux/Linuxgeneric | 3.8 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Published upstream
Jul 28, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_qfq: Fix race condition on qfq_aggregate A race condition can occur when 'agg' is modified in qfq_change_agg (called during qfq_enqueue) while other threads access it concurrently. For example, qfq_dump_class may trigger a NULL dereference, and qfq_delete_class may cause a use-after-free. This patch addresses the issue by: 1. Moved qfq_destroy_class into the critical section. 2. Added sch_tree_lock protection to qfq_dump_class and qfq_dump_class_stats.
Quoted source text, attributed separately from HOL analysis.