Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-37752

25
FAUCET Score

CVE-2025-37752 is a high-severity array-index-out-of-bounds vulnerability in the Linux kernel's net_sched subsystem, specifically within the sch_sfq component. It affects Debian and Linux kernel versions, allowing a local attacker with low privileges to cause a denial of service or potentially escalate privileges. The vulnerability arises from insufficient validation of the 'limit' parameter during configuration updates, leading to an out-of-bounds write. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.1.129, < 6.1.135CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6.76, < 6.6.88CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.12.13, < 6.12.24CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13.2, < 6.13.12CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.14, < 6.14.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.23%
Probability of exploitation in next 30 days
EPSS Percentile
14.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0023 is in the 46th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

autodeskpatch availablevia llm_extracted
View patch
feathersjspatch availablevia llm_extracted
View patch
freepbxpatch availablevia llm_extracted
View patch
honeywellpatch availablevia llm_extracted
View patch
sophospatch availablevia llm_extracted
View patch

Vendor Advisories (6)

honeywellllm-honeywell-c82b5cfda9df97a3CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
autodeskllm-autodesk-c365b674a2ff5a3aCRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
freepbxllm-freepbx-e54908c7967265f6CRITICAL

HP ThinPro 8.1 SP8 Security Updates

Oct 27, 2025
feathersjsllm-feathersjs-2fdea160c475a2bfHIGH

Linux kernel privilege escalation on Container-Optimized OS nodes (CVE-2025-37752)

Sep 25, 2025
sophosllm-sophos-919cef70f554a681HIGH

Linux kernel privilege escalation on Container-Optimized OS nodes

Jul 9, 2025
redhatCVE-2025-37752Moderate

kernel: net_sched: sch_sfq: move the limit validation

May 1, 2025

References

git.kernel.org / stable/c/1348214fa042a71406964097e743c87a42c85a49
Patch
git.kernel.org / stable/c/5e5e1fcc1b8ed57f902c424c5d9b328a3a19073d
Patch
git.kernel.org / stable/c/6c589aa318023690f1606c666a7fb5f4c1c9c219
Patch
git.kernel.org / stable/c/7d62ded97db6b7c94c891f704151f372b1ba4688
Patch
git.kernel.org / stable/c/8fadc871a42933aacb7f1ce9ed9a96485e2c9cf4
Patch
git.kernel.org / stable/c/b36a68192037d1614317a09b0d78c7814e2eecf9
Patch
git.kernel.org / stable/c/b3bf8f63e6179076b57c9de660c9f80b5abefe70
Patch
git.kernel.org / stable/c/d2718324f9e329b10ddc091fba5a0ba2b9d4d96a
Patch
git.kernel.org / stable/c/f86293adce0c201cfabb283ef9d6f21292089bb8
Patch
lists.debian.org / debian-lts-announce/2025/05/msg00045.html
Mailing List