In the Linux kernel, the following vulnerability has been resolved:
netsched: hfsc: Fix a potential UAF in hfscdequeue() too
Similarly to the previous patch, we need to safe guard hfsc_dequeue() too. But for this one, we don't have a reliable reproducer.
[
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-1d45c728",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ccbda44e2cc3d26fd22af54c650d6d5d801addf",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-1fe047cf",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6936266f8bf98a53f28ef9a820e6a501e946d09",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-1fe64abd",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f46d14919c39528c6e540ebc43f90055993eedc",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-30718074",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@68f256305ceb426d545a0dc31f83c2ab1d211a1e",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-319d1359",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6f035044104c6ff656f4565cd22938dc892528c",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-3a61a633",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6936266f8bf98a53f28ef9a820e6a501e946d09",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-3b7c0724",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11bccb054c1462fb069219f8e98e97a5a730758e",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-4e7de646",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@11bccb054c1462fb069219f8e98e97a5a730758e",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"length": 948.0,
"function_hash": "303811518236293401059524248041527814881"
},
"signature_type": "Function",
"id": "CVE-2025-37823-7a88f887",
"target": {
"file": "net/sched/sch_hfsc.c",
"function": "hfsc_dequeue"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76c4c22c2437d3d3880efc0f62eca06ef078d290",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-7e51c48b",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c6f035044104c6ff656f4565cd22938dc892528c",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-ae79651a",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6ccbda44e2cc3d26fd22af54c650d6d5d801addf",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-d2a105e9",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f46d14919c39528c6e540ebc43f90055993eedc",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-de0f1284",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76c4c22c2437d3d3880efc0f62eca06ef078d290",
"deprecated": false
},
{
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"8569283475718205381266243281395088603",
"171711015978558969689116592543007279582",
"33702060334131480047315256987885313819",
"289068028132463892150705727840184378343",
"249332745092491763790958832918785913078",
"140181723247829081125711196450828810872",
"51484024624600550625927369612634653937"
]
},
"signature_type": "Line",
"id": "CVE-2025-37823-fe974bb2",
"target": {
"file": "net/sched/sch_hfsc.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@68f256305ceb426d545a0dc31f83c2ab1d211a1e",
"deprecated": false
}
]