CVE-2025-37953 - CVE House
Back to Database
Status published Unknown CVE-2025-37953

sch_htb: make htb_deactivate() idempotent

Vulnerability Description

In the Linux kernel, the following vulnerability has been resolved: sch_htb: make htb_deactivate() idempotent Alan reported a NULL pointer dereference in htb_next_rb_node() after we made htb_qlen_notify() idempotent. It turns out in the following case it introduced some regression: htb_dequeue_tree(): |-> fq_codel_dequeue() |-> qdisc_tree_reduce_backlog() |-> htb_qlen_notify() |-> htb_deactivate() |-> htb_next_rb_node() |-> htb_deactivate() For htb_next_rb_node(), after calling the 1st htb_deactivate(), the clprio[prio]->ptr could be already set to NULL, which means htb_next_rb_node() is vulnerable here. For htb_deactivate(), although we checked qlen before calling it, in case of qlen==0 after qdisc_tree_reduce_backlog(), we may call it again which triggers the warning inside. To fix the issues here, we need to: 1) Make htb_deactivate() idempotent, that is, simply return if we already call it before. 2) Make htb_next_rb_node() safe against ptr==NULL. Many thanks to Alan for testing and for the reproducer.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-37953

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Linux
Vulnerable Versions:
e6b45f4de763b00dc1c55e685e2dd1aaf525d3c1, 32ae12ce6a9f6bace186ca7335220ff59b6cc3cd, 967955c9e57f8eebfccc298037d4aaf3d42bc1c9, 73cf6af13153d62f9b76eff422eea79dbc70f15e, bbbf5e0f87078b715e7a665d662a2c0e77f044ae, 0a188c0e197383683fd093ab1ea6ce9a5869a6ea, a61f1b5921761fbaf166231418bc1db301e5bf59, 5ba8b837b522d7051ef81bacf3d95383ff8edce5, 6.1.138, 6.6.90, 6.12.28, 6.14.6

Timeline

Official Publish: May 20th, 2025
Last Modified: May 11th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.