CVE-2025-37752 is a high-severity array-index-out-of-bounds vulnerability in the Linux kernel's net_sched subsystem, specifically within the sch_sfq component. It affects Debian and Linux kernel versions, allowing a local attacker with low privileges to cause a denial of service or potentially escalate privileges. The vulnerability arises from insufficient validation of the 'limit' parameter during configuration updates, leading to an out-of-bounds write. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.129, < 6.1.135CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.6.76, < 6.6.88CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.12.13, < 6.12.24CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13.2, < 6.13.12CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.14, < 6.14.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025Linux kernel privilege escalation on Container-Optimized OS nodes (CVE-2025-37752)
Sep 25, 2025Linux kernel privilege escalation on Container-Optimized OS nodes
Jul 9, 2025kernel: net_sched: sch_sfq: move the limit validation
May 1, 2025