In the Linux kernel, the following vulnerability has been resolved: net_sched: ets: Fix double list add in class with netem as child qdisc As described in Gerrard's report [1], there are use cases where a netem child qdisc will make the parent qdisc's enqueue callback reentrant. In the case of ets, there won't be a UAF, but the code will add the same classifier to the list twice, which will cause memory corruption. In addition to checking for qlen being zero, this patch checks whether the class was already added to the active_list (cl_is_active) before doing the addition to cater for the reentrant case. [1] https://lore.kernel.org/netdev/CAHcdcOm+03OD2j6R0=YHKqmy=VgJ8xEOKuP6c7mSgnp-TEJJbw@mail.gmail.com/
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025052000-CVE-2025-37914-1a4f@gregkh/T
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:13961 https://access.redhat.com/errata/RHSA-2025:13961
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2025:13960 https://access.redhat.com/errata/RHSA-2025:13960
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2025:14420 https://access.redhat.com/errata/RHSA-2025:14420
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2025:14510 https://access.redhat.com/errata/RHSA-2025:14510
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2025:15668 https://access.redhat.com/errata/RHSA-2025:15668
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2025:17570 https://access.redhat.com/errata/RHSA-2025:17570
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:17735 https://access.redhat.com/errata/RHSA-2025:17735
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2025:17734 https://access.redhat.com/errata/RHSA-2025:17734
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2025:18043 https://access.redhat.com/errata/RHSA-2025:18043
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:18054 https://access.redhat.com/errata/RHSA-2025:18054
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2025:18098 https://access.redhat.com/errata/RHSA-2025:18098