CVE-2025-39766
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39766 is a vulnerability in the Linux kernel that was discovered and published on September 11, 2025. The issue affects the network scheduling subsystem, specifically related to the CAKE queueing discipline's packet handling behavior (NVD).

Technical details

The vulnerability occurs in the net/sched component where cakeenqueue returns NETXMITSUCCESS instead of NETXMITCN when packets are dropped due to buffer limits. This incorrect return value can trigger a WARNING in htbactivate when the condition !cl->leaf.q->q.qlen is met. The issue can be reproduced using a specific setup involving traffic control (tc) commands with low memory limits (NVD).

Impact

When exploited, this vulnerability can cause system warnings and potential packet handling issues in network traffic management. The impact is primarily related to network performance and system stability rather than security compromises (NVD).

Mitigation and workarounds

The issue has been fixed in newer kernel versions, where cakeenqueue now correctly returns NETXMIT_CN when packets are dropped from the same tin and flow. The fix ensures proper congestion signaling behavior (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-modules-internal
NoYesDec 09, 2025
CVE-2025-40343N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoYesDec 09, 2025
CVE-2025-40342N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoYesDec 09, 2025
CVE-2025-40341N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40340N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management