CVE-2025-37992: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net_sched: Flush gso_skb list too during ->change() Previously, when reducing a qdisc's limit via the ->change() operation, only the main skb queue was trimmed, potentially leaving packets in the gso_skb list. This could result in NULL pointer dereference when we only check sch->limit against sch->q.qlen. This patch introduces a new helper, qdisc_dequeue_internal(), which ensures both the gso_skb list and the main queue are properly flushed when trimming excess packets. All relevant qdiscs (codel, fq, fq_codel, fq_pie, hhf, pie) are updated to use this helper in their ->change() routines.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 3.5, before 5.10.238 (fixed in 5.10.238); from 5.11, before 5.15.184 (fixed in 5.15.184); from 5.16, before 6.1.140 (fixed in 6.1.140); from 6.2, before 6.6.92 (fixed in 6.6.92); from 6.7, before 6.12.30 (fixed in 6.12.30); from 6.13, before 6.14.8 (fixed in 6.14.8); …

Published 2025-05-26. Last modified 2026-06-17.