Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The… (CVE-2025-39766)
In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The following setup can trigger a WARNING in htb_activate due to the condition: !cl->leaf.q->q.qlen tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev lo parent 1: classid 1:1 \ htb rate 64bit tc qdisc add dev lo parent 1:1 handle f: \ cake memlimit 1b ping -I lo -f -c1 -s64 -W0.001 127.0.0.1 This is because the low memlimit leads to a low buffer_limit, which causes packet dropping. However, cake_enqueue still returns NET_XMIT_SUCCESS, causing htb_enqueue to call htb_activate with an empty child qdisc. We should return NET_XMIT_CN when packets are dropped from the same tin and flow. I do not believe return value of NET_XMIT_CN is necessary for packet drops in the case of ack filtering, as that is meant to optimize performance, not to signal congestion.
AI Analysis
Technical Summary
This advisory covers multiple security fixes in the Red Hat Enterprise Linux Real Time kernel (kernel-rt), including CVE-2025-39766 where the cake_enqueue function in net/sched returns NET_XMIT_CN when past buffer_limit, and several use-after-free vulnerabilities in traffic control (act_ct, CVE-2026-23270) and bonding driver (CVE-2026-31419) that may cause denial of service or privilege escalation. Additional fixes address clearing skb2->cb[] in ip6_tunnel and ipv6 ICMP error handling (CVE-2026-43037, CVE-2026-43038), validation of DACL in smb client (CVE-2026-31709), and a race condition causing a general protection fault in md/bitmap (CVE-2026-43163). The advisory references Red Hat Enterprise Linux 9.2 Real Time variants and provides updated packages to remediate these issues.
Potential Impact
The vulnerabilities fixed in this update can lead to denial of service conditions or privilege escalation on affected systems running the Red Hat Enterprise Linux Real Time kernel. Use-after-free bugs in kernel components may allow attackers to crash the system or escalate privileges. Improper handling of network packet buffers and access control lists could also compromise system stability or security.
Mitigation Recommendations
Red Hat has released an official security update for the kernel-rt packages addressing these vulnerabilities. Users should apply the update as provided in Red Hat Advisory RHSA-2026:22900 and reboot the system to ensure the fixes take effect. No additional mitigation steps are indicated beyond applying the official patch.
Linux hwe edge: In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The… (CVE-2025-39766)
Description
In the Linux kernel, the following vulnerability has been resolved: net/sched: Make cake_enqueue return NET_XMIT_CN when past buffer_limit The following setup can trigger a WARNING in htb_activate due to the condition: !cl->leaf.q->q.qlen tc qdisc del dev lo root tc qdisc add dev lo root handle 1: htb default 1 tc class add dev lo parent 1: classid 1:1 \ htb rate 64bit tc qdisc add dev lo parent 1:1 handle f: \ cake memlimit 1b ping -I lo -f -c1 -s64 -W0.001 127.0.0.1 This is because the low memlimit leads to a low buffer_limit, which causes packet dropping. However, cake_enqueue still returns NET_XMIT_SUCCESS, causing htb_enqueue to call htb_activate with an empty child qdisc. We should return NET_XMIT_CN when packets are dropped from the same tin and flow. I do not believe return value of NET_XMIT_CN is necessary for packet drops in the case of ack filtering, as that is meant to optimize performance, not to signal congestion.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This advisory covers multiple security fixes in the Red Hat Enterprise Linux Real Time kernel (kernel-rt), including CVE-2025-39766 where the cake_enqueue function in net/sched returns NET_XMIT_CN when past buffer_limit, and several use-after-free vulnerabilities in traffic control (act_ct, CVE-2026-23270) and bonding driver (CVE-2026-31419) that may cause denial of service or privilege escalation. Additional fixes address clearing skb2->cb[] in ip6_tunnel and ipv6 ICMP error handling (CVE-2026-43037, CVE-2026-43038), validation of DACL in smb client (CVE-2026-31709), and a race condition causing a general protection fault in md/bitmap (CVE-2026-43163). The advisory references Red Hat Enterprise Linux 9.2 Real Time variants and provides updated packages to remediate these issues.
Potential Impact
The vulnerabilities fixed in this update can lead to denial of service conditions or privilege escalation on affected systems running the Red Hat Enterprise Linux Real Time kernel. Use-after-free bugs in kernel components may allow attackers to crash the system or escalate privileges. Improper handling of network packet buffers and access control lists could also compromise system stability or security.
Mitigation Recommendations
Red Hat has released an official security update for the kernel-rt packages addressing these vulnerabilities. Users should apply the update as provided in Red Hat Advisory RHSA-2026:22900 and reboot the system to ensure the fixes take effect. No additional mitigation steps are indicated beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:9264
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-68741"]
- Cvss Version
- null
Threat ID: 6a175eede29bf47b50edbf3d
Added to database: 05/27/2026, 21:15:25 UTC
Last enriched: 07/07/2026, 00:18:18 UTC
Last updated: 08/10/2026, 12:41:07 UTC
Views: 87
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.