{
  "schema_version": "1.6.1",
  "id": "RPI-CVE-2025-21703",
  "modified": "2026-10-07T17:22:01Z",
  "upstream": [
    "CVE-2025-21703"
  ],
  "published": "2025-02-18T14:38:11Z",
  "summary": "netem: Update sch->q.qlen before qdisc_tree_reduce_backlog()",
  "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetem: Update sch->q.qlen before qdisc_tree_reduce_backlog()\n\nqdisc_tree_reduce_backlog() notifies parent qdisc only if child\nqdisc becomes empty, therefore we need to reduce the backlog of the\nchild qdisc before calling it. Otherwise it would miss the opportunity\nto call cops->qlen_notify(), in the case of DRR, it resulted in UAF\nsince DRR uses ->qlen_notify() to maintain its active list.",
  "affected": [
    {
      "package": {
        "ecosystem": "Raspberry Pi OS:12",
        "name": "linux"
      },
      "versions": [
        "1:6.6.74-1+rpt1"
      ],
      "ecosystem_specific": {
        "binaries": [
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-2712",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v6",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v7",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v7l",
            "binary_version": "1:6.6.74-1+rpt1"
          },
          {
            "binary_name": "linux-image-6.6.74+rpt-rpi-v8",
            "binary_version": "1:6.6.74-1+rpt1"
          }
        ]
      },
      "database_specific": {
        "per_version": {
          "1:6.6.74-1+rpt1": {
            "linux_commit": "a18d9ced4965462cb7b3b4252ada440395105308",
            "upstream_version": "6.6.74",
            "assessment": "commit ancestry (strak rule)",
            "upstream_fixed": "6.6.78"
          }
        }
      }
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-21703"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/e395fec75ac2dbffc99b4bce57b7f1f3c5449f2c"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/7f31d74fcc556a9166b1bb20515542de7bb939d1"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/98a2c685293aae122f688cde11d9334dddc5d207"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/7b79ca9a1de6a428d486ff52fb3d602321c08f55"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/1f8e3f4a4b8b90ad274dfbc66fc7d55cb582f4d5"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/6312555249082d6d8cc5321ff725df05482d8b83"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/839ecc583fa00fab785fde1c85a326743657fd32"
    },
    {
      "type": "FIX",
      "url": "https://git.kernel.org/stable/c/638ba5089324796c2ee49af10427459c2de35f71"
    }
  ],
  "database_specific": {
    "source": "https://git.kernel.org/pub/scm/linux/security/vulns.git",
    "upstream_modified": "2026-08-05T12:19:11Z"
  }
}
