CVE-2025-38684 is a moderate-severity flaw in the Linux kernel's Enhanced Transmission Selection (ETS) traffic-control scheduler. A faulty update sequence in ets_qdisc_change() updates q->nbands before unused DWRR classes are purged, leaving cleanup logic to operate on an inconsistent ETS configuration and potentially dereference a NULL pointer. A local attacker can trigger a kernel crash, resulting in denial of service; Red Hat rates the issue CVSS 5.2, while NVD assigns 5.5.
Red Hat has released fixes for standard kernels in RHEL 8, RHEL 9, and RHEL 10. Fixes for the RHEL 8 and RHEL 9 real-time kernels remain deferred, while RHEL 6, RHEL 7, and the RHEL 7 real-time kernel are not affected because they lack the vulnerable code. Organizations using affected kernel packages should apply the available updates and plan mitigation for affected real-time deployments until fixes are released.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:15447, fixing CVE-2025-38684 in the standard RHEL 10 kernel.
Red Hat published CVE-2025-38684 for a NULL-pointer dereference in the Linux kernel ETS traffic-control scheduler. The flaw can allow a local attacker to cause a kernel crash and denial of service during queue-discipline modification.
Red Hat released RHSA-2025:15035 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernels, and RHSA-2025:15011 for the standard RHEL 9 kernel, addressing the ETS scheduler NULL-pointer dereference flaw.
Red Hat released RHSA-2025:15785, fixing CVE-2025-38684 in the standard RHEL 8 kernel.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.