CVE-2025-21647·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-host bulk flow counters, leading to an out of bounds memory access. To avoid any such logic errors causing out of bounds memory accesses, this commit factors out all accesses to the per-host bulk flow counters to a series of helpers that perform bounds-checking before any increments and decrements. This also has the benefit of improving readability by moving the conditional checks for the flow mode into these helpers, instead of having them spread out throughout the code (which was the cause of the original logic error). As part of this change, the flow quantum calculation is consolidated into a helper function, which means that the dithering applied to the ost load scaling is now applied both in the DRR rotation and when a sparse flow's quantum is first initiated. The only user-visible effect of this is that the maximum packet size that can be sent while a flow stays sparse will now vary with +/- one byte in some cases. This should not make a noticeable difference in practice, and thus it's not worth complicating the code to preserve the old behaviour.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.12.10
- Published
- 2025-01-19
Affected versions
From: 6.11.1
Until: 6.12.10
Fixed in: 6.12.10
How to fix this CVE
Update your Linux kernel to version 6.12.10 or later to patch the memory access vulnerability in the CAKE qdisc scheduler. This vulnerability allows local authenticated attackers to trigger an underflow in per-host bulk flow counters, potentially causing kernel crashes or information disclosure. Apply the patch immediately to systems running kernel versions 6.11.1 through 6.12.9.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check your current kernel version with: uname -r
- Step 2: Verify if CAKE qdisc is in use by running: tc qdisc show | grep cake
- Step 3: Search kernel logs for CAKE-related faults using: sudo dmesg | grep -i cake or sudo journalctl -u kernel | grep -i cake
- Step 4: Confirm the patch was applied by checking if kernel version is 6.12.10 or later: uname -r
FAQ
What is CVE-2025-21647?
This vulnerability affects the CAKE (Common Applications Kept Enhanced) network packet scheduling discipline in the Linux kernel. A missing bounds check in per-host bulk flow fairness counters can allow local authenticated users to cause a counter underflow, resulting in out-of-bounds memory access and potential kernel crashes or information leaks.
Is CVE-2025-21647 being actively exploited?
No, CVE-2025-21647 is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits are available.
What versions of Kernel are affected by CVE-2025-21647?
Linux kernel versions 6.11.1 through 6.12.9 are vulnerable. Version 6.12.10 and later contain the fix.
How do I check if my server is vulnerable to CVE-2025-21647?
Run 'uname -r' to check your kernel version. If the output shows a version between 6.11.1 and 6.12.9, your system is vulnerable. Additionally, verify CAKE qdisc usage with 'tc qdisc show | grep cake'.
Does Defensia detect CVE-2025-21647?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server and the version falls within the vulnerable range, CVE-2025-21647 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/27202e2e8721c3b23831563c36ed5ac7818641ba
- https://git.kernel.org/stable/c/44fe1efb4961c1a5ccab16bb579dfc6b308ad58b
- https://git.kernel.org/stable/c/737d4d91d35b5f7fa5bb442651472277318b0bfd
- https://git.kernel.org/stable/c/91bb18950b88f955838ec0c1d97f74d135756dc7
- https://git.kernel.org/stable/c/a777e06dfc72bed73c05dcb437d7c27ad5f90f3f
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-21647. Free for 1 server.
Get started free