Skip to main content

Threats Tagged 'cve-2025-38380'

View all threats tagged with 'cve-2025-38380'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2025-38380

Threats Tagged 'cve-2025-38380'

Click on any threat for detailed analysis and mitigation recommendations

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-477.67.1.el8_8. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-553.16.1.el8_10. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-372.118.1.el8_6. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-427.44.1.el9_4. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-284.104.1.el9_2. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-5.14.0-70.124.1.el9_0. Security Fix(es): * kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) * kernel: net_sched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) * kernel: sch_hfsc: Fix qlen accounting bug when using peek in hfsc_enqueue() (CVE-2025-38000) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) * kernel: tls: always refresh the queue when reading sock (CVE-2025-38471) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type() (CVE-2025-21867) * kernel: net: fix udp gso skb_segment after pull from frag_list (CVE-2025-38124) * kernel: Bluetooth: hci_core: Fix use-after-free in vhci_flush() (CVE-2025-38250) * kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) * kernel: tls: always refresh the queue when reading sock (CVE-2025-38471) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc As described in Gerrard's report [1], we have a UAF case when an hfsc class has a netem child qdisc. The crux of the issue is that hfsc is assuming that checking for cl->qdisc->q.qlen == 0 guarantees that it hasn't inserted the class in the vttree or eltree (which is not true for the netem duplicate case). This patch checks the n_active class variable to make sure that the code won't insert the class in the vttree or eltree twice, catering for the reentrant case. [1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/

Join the discussion

CVE-2024-28956 is an information disclosure vulnerability affecting some Intel processors. It involves exposure of sensitive information through shared microarchitectural structures during transient execution. The vulnerability requires local authenticated access and has a medium severity rating with a CVSS score of 5.7. Red Hat has released updates for the Linux kernel and microcode_ctl packages to address this issue in Red Hat Enterprise Linux 9. Users must apply these updates and reboot their systems to mitigate the vulnerability.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Tag: cve-2025-38380
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses