#VU115584 Resource management error in Linux kernel - CVE-2025-39766
Published: September 16, 2025
Vulnerability identifier: #VU115584
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-39766
CWE-ID: CWE-399
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerable software:
Linux kernel
Linux kernel
Software vendor:
Linux Foundation
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the cake_enqueue() function in net/sched/sch_cake.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's repository.
External links
- https://git.kernel.org/stable/c/0dacfc5372e314d1219f03e64dde3ab495a5a25e
- https://git.kernel.org/stable/c/15de71d06a400f7fdc15bf377a2552b0ec437cf5
- https://git.kernel.org/stable/c/62d591dde4defb1333d202410609c4ddeae060b3
- https://git.kernel.org/stable/c/710866fc0a64eafcb8bacd91bcb1329eb7e5035f
- https://git.kernel.org/stable/c/7689ab22de36f8db19095f6bdf11f28cfde92f5c
- https://git.kernel.org/stable/c/aa12ee1c1bd260943fd6ab556d8635811c332eeb
- https://git.kernel.org/stable/c/de04ddd2980b48caa8d7e24a7db2742917a8b280
- https://git.kernel.org/stable/c/ff57186b2cc39766672c4c0332323933e5faaa88