CVE-2025-21647
Linux Kernel vulnerability analysis and mitigation

Overview

In the Linux kernel, a vulnerability (CVE-2025-21647) was discovered in the sch_cake module affecting the host bulk flow fairness counts. The issue was identified when syzbot triggered an underflow of the per-host bulk flow counters, leading to an out-of-bounds memory access. This vulnerability was reported on January 19, 2025, and affects various Linux kernel versions (NVD, Debian Tracker).

Technical details

The vulnerability stems from a logic error in the host bulk flow counter handling within the sch_cake module. When processing network traffic, the code could trigger an underflow of the per-host bulk flow counters, resulting in out-of-bounds memory access. The issue occurs despite previous fixes, indicating a deeper architectural problem in how the flow counters are managed (Kernel Commit).

Impact

The vulnerability could lead to out-of-bounds memory access in the Linux kernel's network scheduling component. This could potentially result in system crashes, memory corruption, or possible privilege escalation, though the exact impact depends on the specific exploitation conditions (NVD).

Mitigation and workarounds

The issue has been fixed in the Linux kernel through a patch that adds bounds checks to host bulk flow fairness counts. The fix involves factoring out all accesses to the per-host bulk flow counters into a series of helpers that perform bounds-checking before any increments and decrements. The patch is available in various kernel versions, including 6.1.128-1 for Debian bookworm (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68764N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug
NoYesJan 05, 2026
CVE-2025-68758N/AN/A
  • Linux KernelLinux Kernel
  • linux-riscv
NoYesJan 05, 2026
CVE-2025-68756N/AN/A
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68753N/AN/A
  • Linux KernelLinux Kernel
  • python3-perf
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management