{"id":"DEBIAN-CVE-2025-38278","details":"In the Linux kernel, the following vulnerability has been resolved:  octeontx2-pf: QOS: Refactor TC_HTB_LEAF_DEL_LAST callback  This patch addresses below issues,  1. Active traffic on the leaf node must be stopped before its send queue    is reassigned to the parent. This patch resolves the issue by marking    the node as 'Inner'.  2. During a system reboot, the interface receives TC_HTB_LEAF_DEL    and TC_HTB_LEAF_DEL_LAST callbacks to delete its HTB queues.    In the case of TC_HTB_LEAF_DEL_LAST, although the same send queue    is reassigned to the parent, the current logic still attempts to update    the real number of queues, leadning to below warnings          New queues can't be registered after device unregistration.         WARNING: CPU: 0 PID: 6475 at net/core/net-sysfs.c:1714         netdev_queue_update_kobjects+0x1e4/0x200","modified":"2026-08-27T23:05:21.697483625Z","published":"2025-07-10T08:15:26.123Z","upstream":["CVE-2025-38278"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38278"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38278.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38278.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}