
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40083 is a vulnerability discovered in the Linux kernel's networking scheduler component (net/sched). The vulnerability was disclosed on October 29, 2025, affecting the Quick Fair Queueing (QFQ) scheduler implementation. The issue specifically involves a null pointer dereference in the aggdequeue function within the net/sched/schqfq.c file (NVD, Red Hat).
The vulnerability stems from a null pointer dereference in the aggdequeue function when cl->qdisc->ops->peek(cl->qdisc) returns NULL. The issue occurs in the net/sched/schqfq.c file of the Linux kernel. The vulnerability has been assigned a CVSS v3 base score of 5.5, indicating moderate severity. Red Hat has classified this as a moderate security issue (Red Hat).
The vulnerability could potentially lead to a system crash when the affected component is triggered, resulting in a denial of service condition. The issue affects various versions of Red Hat Enterprise Linux, including versions 6 through 10 (Red Hat).
A fix has been implemented that involves checking the return value before using it, similar to the existing approach in schhfsc.c. The solution includes changing qdiscwarnnonwc into a static inline function, moving qdiscpeeklen from net/sched/schhfsc.c to include/net/pktsched.h, and applying qdiscpeeklen in aggdequeue to prevent crashes (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."