
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39766 is a vulnerability in the Linux kernel that was discovered and published on September 11, 2025. The issue affects the network scheduling subsystem, specifically related to the CAKE queueing discipline's packet handling behavior (NVD).
The vulnerability occurs in the net/sched component where cakeenqueue returns NETXMITSUCCESS instead of NETXMITCN when packets are dropped due to buffer limits. This incorrect return value can trigger a WARNING in htbactivate when the condition !cl->leaf.q->q.qlen is met. The issue can be reproduced using a specific setup involving traffic control (tc) commands with low memory limits (NVD).
When exploited, this vulnerability can cause system warnings and potential packet handling issues in network traffic management. The impact is primarily related to network performance and system stability rather than security compromises (NVD).
The issue has been fixed in newer kernel versions, where cakeenqueue now correctly returns NETXMIT_CN when packets are dropped from the same tin and flow. The fix ensures proper congestion signaling behavior (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."