CVE-2025-38278
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2025
Last modified:
19/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback<br />
<br />
This patch addresses below issues,<br />
<br />
1. Active traffic on the leaf node must be stopped before its send queue<br />
is reassigned to the parent. This patch resolves the issue by marking<br />
the node as &#39;Inner&#39;.<br />
<br />
2. During a system reboot, the interface receives TC_HTB_LEAF_DEL<br />
and TC_HTB_LEAF_DEL_LAST callbacks to delete its HTB queues.<br />
In the case of TC_HTB_LEAF_DEL_LAST, although the same send queue<br />
is reassigned to the parent, the current logic still attempts to update<br />
the real number of queues, leadning to below warnings<br />
<br />
New queues can&#39;t be registered after device unregistration.<br />
WARNING: CPU: 0 PID: 6475 at net/core/net-sysfs.c:1714<br />
netdev_queue_update_kobjects+0x1e4/0x200
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.5 (including) | 6.6.94 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.34 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.15.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



