CVE-2025-39677: net/sched: Fix backlog accounting in qdisc_dequeue_internal

Published Sep 5, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net/sched: Fix backlog accounting in qdiscdequeueinternal

This issue applies for the following qdiscs: hhf, fq, fqcodel, and fqpie, and occurs in their change handlers when adjusting to the new limit. The problem is the following in the values passed to the subsequent qdisctreereducebacklog call given a tbf parent:

When the tbf parent runs out of tokens, skbs of these qdiscs will be placed in gsoskb. Their peek handlers are qdiscpeekdequeued, which accounts for both qlen and backlog. However, in the case of qdiscdequeueinternal, ONLY qlen is accounted for when pulling from gsoskb. This means that these qdiscs are missing a qdiscqstatsbacklogdec when dropping packets to satisfy the new limit in their change handlers.

One can observe this issue with the following (with tc patched to support a limit of 0):

export TARGET=fq tc qdisc del dev lo root tc qdisc add dev lo root handle 1: tbf rate 8bit burst 100b latency 1ms tc qdisc replace dev lo handle 3: parent 1:1 $TARGET limit 1000 echo ''; echo 'add child'; tc -s -d qdisc show dev lo ping -I lo -f -c2 -s32 -W0.001 127.0.0.1 2>&1 >/dev/null echo ''; echo 'after ping'; tc -s -d qdisc show dev lo tc qdisc change dev lo handle 3: parent 1:1 $TARGET limit 0 echo ''; echo 'after limit drop'; tc -s -d qdisc show dev lo tc qdisc replace dev lo handle 2: parent 1:1 sfq echo ''; echo 'post graft'; tc -s -d qdisc show dev lo

The second to last show command shows 0 packets but a positive number (74) of backlog bytes. The problem becomes clearer in the last show command, where qdiscpurgequeue triggers qdisctreereducebacklog with the positive backlog and causes an underflow in the tbf parent's backlog (4096 Mb instead of 0).

To fix this issue, the codepath for all clients of qdiscdequeueinternal has been simplified: codel, pie, hhf, fq, fqpie, and fqcodel. qdiscdequeueinternal handles the backlog adjustments for all cases that do not directly use the dequeue handler.

The old fqcodelchange limit adjustment loop accumulated the arguments to the subsequent qdisctreereducebacklog call through the cstats field. However, this is confusing and error prone as fqcodeldequeue could also potentially mutate this field (which qdiscdequeueinternal calls in the non gsoskb case), so we have unified the code here with other qdiscs.

Affected Software

11 affected components
Linux Kernel
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Linux Linux kernel>=3.5<6.16.4
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Microsoft azl3 kernel 6.6.104.2-4
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.117.1-1
Microsoft azl3 kernel 6.6.119.3-1

Event History

Sep 5, 2025
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverity
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityAffected Software
Sep 7, 2025
Data Sourced
via Microsoft·01:09 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:09 AM
Affected Software
Updated
via Microsoft·01:09 AM
SeverityAffected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity

Frequently Asked Questions

1

What is the severity of CVE-2025-39677?

The severity of CVE-2025-39677 is considered medium due to potential impact on network scheduling functionality.

2

How do I fix CVE-2025-39677?

To fix CVE-2025-39677, update your Linux kernel to the latest patched version provided by your distribution.

3

What systems are affected by CVE-2025-39677?

CVE-2025-39677 affects various qdiscs in the Linux kernel, specifically hhf, fq, fq_codel, and fq_pie.

4

Can CVE-2025-39677 be exploited remotely?

CVE-2025-39677 may allow an attacker to exploit the vulnerability remotely, affecting the performance of network queues.

5

What are the symptoms of CVE-2025-39677 being exploited?

Symptoms of CVE-2025-39677 exploitation may include unusual network performance issues or packet loss due to mismanaged queue limits.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203