PatchSiren cyber security CVE debrief
CVE-2025-71066 Linux CVE debrief
CVE-2025-71066 is a Linux kernel net/sched ETS qdisc race condition that can leave a class on the active list after its qdisc has been freed, creating a use-after-free in struct Qdisc. The supplied source says an attacker needs the ability to create new user and network namespaces to trigger the bug. The referenced fix removes the class from the active list before deleting and freeing the associated qdisc.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-13
- Original CVE updated
- 2026-07-30
- Advisory published
- 2026-01-13
- Advisory updated
- 2026-07-30
Who should care
Linux kernel maintainers, distro security teams, and operators of systems that allow unprivileged user and network namespace creation should prioritize this issue, especially where tc/ets traffic shaping is used.
Technical summary
The vulnerability is described as a race between ets_qdisc_dequeue and ets_qdisc_change. During ETS reconfiguration, a class can remain linked in the active list while its qdisc pointer is cleared and the qdisc object is freed after the lock is released. If dequeue runs in that window, it can follow a stale active-list entry and dereference freed qdisc state, resulting in a use-after-free in struct Qdisc. The stated fix is to always remove the class from the active list before deleting and freeing its associated qdisc.
Defensive priority
High
Recommended defensive actions
- Apply the Linux kernel fix associated with the linked stable commits for CVE-2025-71066.
- Review systems that use ETS qdisc configurations and ensure kernel packages are updated from a trusted vendor build.
- Reduce exposure by limiting unprivileged user namespace and network namespace creation where operationally feasible.
- Prioritize hosts that support local users, containers, or other workloads that can reach tc and namespace functionality.
- Track vendor and distribution advisories for backported fixes that correspond to the linked kernel.org commit references.
Evidence notes
The supplied description explicitly identifies a race between ets_qdisc_dequeue and ets_qdisc_change, states that some classes remain on the active list after their qdisc is set to NULL, and links that state to a use-after-free on struct Qdisc. The source item also provides kernel.org stable commit references associated with the fix, while the NVD record is marked Deferred and does not supply a CVSS vector or version range in the provided corpus. CVE publication timing in the supplied timeline is 2026-01-13, with a later record modification on 2026-04-15.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-71066 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-71066
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-71066 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-71066
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/062d5d544e564473450d72e6af83077c2b2ff7c3
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/06bfb66a7c8b45e3fed01351a4b087410ae5ef39
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/45466141da3c98a0c5fa88be0bc14b4b6a4bd75c
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9987cda315c08f63a02423fa2f9a1f6602c861a0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a75d617a4ef08682f5cfaadc01d5141c87e019c9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c7f6e7cc14df72b997258216e99d897d2df0dbbd
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/ce052b9402e461a9aded599f5b47e76bc727f7de
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.