Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-37823

CVE-2025-37823: Linux Kernel Use-After-Free Vulnerability

CVE-2025-37823 is a use-after-free vulnerability in the Linux Kernel's net_sched hfsc_dequeue() function that could allow memory corruption. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2025-37823 Overview

CVE-2025-37823 is a use-after-free vulnerability in the Linux kernel's Hierarchical Fair Service Curve (HFSC) network queueing discipline. The flaw affects the hfsc_dequeue() function inside net/sched/sch_hfsc.c and follows a related fix applied to the HFSC enqueue path. A local attacker with the ability to configure network traffic control can trigger the condition to corrupt kernel memory. The issue was resolved upstream by adding safeguards around packet handling in the dequeue routine. The vulnerability is categorized under CWE-416: Use After Free.

Critical Impact

Local, low-privilege attackers can trigger a kernel use-after-free in the HFSC scheduler, enabling potential privilege escalation or full system compromise.

Affected Products

  • Linux kernel (multiple stable branches through 6.15-rc3)
  • Linux kernel line originating at version 2.6.12
  • Debian GNU/Linux 11 (Bullseye)

Discovery Timeline

  • 2025-05-08 - CVE-2025-37823 published to the National Vulnerability Database
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2025-37823

Vulnerability Analysis

The HFSC queueing discipline implements hierarchical bandwidth scheduling in the Linux traffic control subsystem. The hfsc_dequeue() function pulls packets from child qdiscs for transmission. A prior fix addressed a use-after-free condition in the enqueue path, but the dequeue path retained a parallel unsafe access pattern. Under specific timing conditions, a socket buffer (sk_buff) or child qdisc reference can be freed while hfsc_dequeue() still holds and dereferences the pointer. This mirrors the previously patched enqueue defect, though no reliable reproducer was published for the dequeue variant.

Root Cause

The root cause is missing lifetime protection around packet or class structures accessed inside hfsc_dequeue(). The scheduler assumed the referenced object would remain valid for the duration of the dequeue operation. When a peer path removes or requeues the object concurrently, the outstanding pointer in hfsc_dequeue() becomes dangling. Subsequent access reads or writes freed memory, matching the [CWE-416] pattern. The upstream fix, distributed across commits such as 68f256305ceb, 76c4c22c2437, and da7936518996, adds the same guard logic used for hfsc_enqueue().

Attack Vector

Exploitation requires local access and the CAP_NET_ADMIN capability, typically available within unprivileged user namespaces on default Debian and mainline configurations. An attacker configures an HFSC qdisc using tc (traffic control) and manipulates class hierarchies and packet flow to race the dequeue path. Successful exploitation of a kernel [CWE-416] issue commonly yields heap primitive control leading to local privilege escalation. See the Debian LTS Announcement and the Kernel Git Commit Log for the corrected code path.

Detection Methods for CVE-2025-37823

Indicators of Compromise

  • Unexpected kernel panics or general protection fault entries in dmesg referencing sch_hfsc.ko or hfsc_dequeue.
  • KASAN use-after-free reports naming the HFSC module in kernel logs.
  • Non-root processes creating user namespaces and invoking tc qdisc add ... hfsc on production systems.

Detection Strategies

  • Audit execve telemetry for tc invocations that configure hfsc qdiscs from non-administrative users or containers.
  • Monitor unshare(CLONE_NEWUSER|CLONE_NEWNET) syscalls followed by traffic control changes, a common local privilege escalation setup.
  • Correlate kernel oops or splat events with recent HFSC configuration activity across fleet endpoints.

Monitoring Recommendations

  • Forward /var/log/kern.log and journald kernel entries to a centralized analytics platform for signature and anomaly matching.
  • Enable KASAN or KFENCE on canary hosts to surface latent use-after-free conditions before production impact.
  • Track kernel version inventory and flag hosts running kernels without the HFSC dequeue patch commits.

How to Mitigate CVE-2025-37823

Immediate Actions Required

  • Apply the latest stable kernel update from your distribution that includes the HFSC dequeue patch.
  • On Debian 11 systems, install the kernel package referenced in the vendor advisory without delay.
  • Restrict CAP_NET_ADMIN and disable unprivileged user namespaces where operationally feasible.

Patch Information

The fix is distributed across multiple stable branches. Reference commits include 11bccb054c14, 2f46d14919c3, 68f256305ceb, 6ccbda44e2cc, 76c4c22c2437, c6936266f8bf, c6f035044104, and da7936518996. Debian users should review the Debian LTS Announcement (msg00030) and Debian LTS Announcement (msg00045) for package versions. Upstream details are available in the Kernel Git Commit Log.

Workarounds

  • Blacklist the sch_hfsc module on systems that do not require HFSC-based traffic shaping.
  • Set kernel.unprivileged_userns_clone=0 to block unprivileged user namespace creation, removing a common local attack primitive.
  • Enforce mandatory access controls (SELinux, AppArmor) to prevent non-administrative users from invoking tc against HFSC qdiscs.
bash
# Prevent loading of the vulnerable module until patched
echo "install sch_hfsc /bin/true" | sudo tee /etc/modprobe.d/disable-hfsc.conf
sudo rmmod sch_hfsc 2>/dev/null

# Disable unprivileged user namespaces
echo "kernel.unprivileged_userns_clone=0" | sudo tee /etc/sysctl.d/99-userns.conf
sudo sysctl --system

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.