ThreatCluster

Multiple CVEs Address UAF Vulnerabilities in BFQ Implementation

First seen 18 Feb 2026, 13:23 UTC Api.Msrc.Microsoft 39

Article Content

Browse articles
ThreatCluster

Three CVEs have been published addressing use-after-free (UAF) vulnerabilities in the BFQ (Budget Fair Queueing) implementation. CVE-2024-49854 and CVE-2024-47706 were published on October 21, 2024, while CVE-2025-21631 was published on January 19, 2025. These vulnerabilities could potentially affect systems utilizing the BFQ scheduler.

Timeline

2024-10-21
CVE-2024-49854 published
2024-10-21
CVE-2024-47706 published
2025-01-19
CVE-2025-21631 published
2026-02-18
Articles published detailing CVEs and fixes