CVE-2025-37890 is a use-after-free flaw in the Linux kernel's Hierarchical Fair Service Curve (HFSC) scheduler when netem is configured as a child queuing discipline. HFSC can wrongly infer that a class is absent from its virtual-time or eligible-time trees when its child queue is empty; netem packet duplication can break that assumption, triggering reentrant insertion and kernel memory corruption. A local attacker able to control queueing-discipline configuration with CAP_NET_ADMIN can crash the host or potentially elevate privileges.
The vulnerability affects kernels from version 5.0 and was fixed upstream in 5.15.182, 6.1.138, 6.6.90, 6.12.28, 6.14.6, and 6.15-rc5. Red Hat rated the issue CVSS 7.0 and warned that ordinary non-root users on RHEL 8 and later may exploit it through unprivileged user namespaces; RHEL 6 and 7 are not affected. Organizations should deploy vendor kernel updates rather than cherry-pick the patch; where immediate patching is not possible, Red Hat recommends preventing the sch_hfsc module from loading.

Get the actors, campaigns, and ATT&CK mapping behind it.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:12662 for RHEL 10 and RHSA-2025:12752 and RHSA-2025:12753 for RHEL 8 and RHEL 8 kernel-rt, respectively, addressing CVE-2025-37890.
Red Hat released RHSA-2025:16582, providing updated RHEL 8 kpatch-patch packages for CVE-2025-37890.
RHSA-2025:15035 fixed CVE-2025-37890 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages.
Red Hat released RHSA-2025:14742 for RHEL 8.2 Advanced Update Support and RHSA-2025:14692 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and SAP update-service systems.
The flaw was fixed in stable Linux versions 5.15.182, 6.1.138, 6.6.90, 6.12.28, 6.14.6, and 6.15-rc5. The fix uses the n_active class variable to prevent duplicate tree insertion.
Commit 37d9cf1 introduced a flaw in the HFSC scheduler that can allow duplicate insertion of a class into virtual-time or eligible-time trees when netem is a child qdisc, causing a use-after-free condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.