In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below…
High CVSS 7.3
Summary
In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-host bulk flow counters, leading to an out of bounds memory access. To avoid any such logic errors causing out of bounds memory accesses, this commit factors out all accesses to the per-host bulk flow counters to a series of helpers that per…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/27202e2e8721c3b23831563c36ed5ac7818641ba Patch
- https://git.kernel.org/stable/c/44fe1efb4961c1a5ccab16bb579dfc6b308ad58b Patch
- https://git.kernel.org/stable/c/737d4d91d35b5f7fa5bb442651472277318b0bfd Patch
- https://git.kernel.org/stable/c/91bb18950b88f955838ec0c1d97f74d135756dc7 Patch
- https://git.kernel.org/stable/c/a777e06dfc72bed73c05dcb437d7c27ad5f90f3f Patch
- https://git.kernel.org/stable/c/b1a1743aaa4906c41c426eda97e2e2586f79246d Patch
- https://git.kernel.org/stable/c/bb0245fa72b783cb23a9949c5048781341e91423 Patch
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://cert-portal.siemens.com/productcert/html/ssa-503939.html
Timeline
- nvd_ingest NVD