CVE-2025-21703: stato di sfruttamento e disponibilità della patch

CVE-2025-21703 · CVSS 7.8 HIGH · EPSS <1%

In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() qdisc_tree_reduce_backlog() notifies parent qdisc only if child qdisc becomes empty, therefore we need to reduce the backlog of the child qdisc before calling it. Otherwise it would miss the opportunity to call cops->qlen_notify(), in the case of DRR, it resulted in UAF since DRR uses ->qlen_notify() to maintain its active list.

CVE-2025-21703 viene sfruttato?

Quali prodotti e versioni sono interessati?

Nessun elenco di pacchetti interessati registrato qui.

Esiste una patch?

Nessun identificativo di patch registrato qui.

Cosa ha pubblicato PlainSec su CVE-2025-21703

Fonti primarie

Cosa questa scheda non dice

KEV ed EPSS vengono ricontrollati ogni giorno. Scheda aggiornata il 2026-08-15.