cbcvebase.
CVE-2025-22119
published 2025-04-16

CVE-2025-22119: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: init wiphy_work before allocating rfkill fails syzbort reported a…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: init wiphy_work before allocating rfkill fails syzbort reported a uninitialize wiphy_work_lock in cfg80211_dev_free. [1] After rfkill allocation fails, the wiphy release process will be performed, which will cause cfg80211_dev_free to access the uninitialized wiphy_work related data. Move the initialization of wiphy_work to before rfkill initialization to avoid this issue. [1] INFO: trying to register non-static key. The code is fine but needs lockdep annotation, or maybe you didn't initialize this object before use? turning off the locking correctness validator. CPU: 0 UID: 0 PID: 5935 Comm: syz-executor550 Not tainted 6.14.0-rc6-syzkaller-00103-g4003c9e78778 #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120 assign_lock_key kernel/locking/lockdep.c:983 [inline] register_lock_class+0xc39/0x1240 kernel/locking/lockdep.c:1297 __lock_acquire+0x135/0x3c40 kernel/locking/lockdep.c:5103 lock_acquire.part.0+0x11b/0x380 kernel/locking/lockdep.c:5851 __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline] _raw_spin_lock_irqsave+0x3a/0x60 kernel/locking/spinlock.c:162 cfg80211_dev_free+0x30/0x3d0 net/wireless/core.c:1196 device_release+0xa1/0x240 drivers/base/core.c:2568 kobject_cleanup lib/kobject.c:689 [inline] kobject_release lib/kobject.c:720 [inline] kref_put include/linux/kref.h:65 [inline] kobject_put+0x1e4/0x5a0 lib/kobject.c:737 put_device+0x1f/0x30 drivers/base/core.c:3774 wiphy_free net/wireless/core.c:1224 [inline] wiphy_new_nm+0x1c1f/0x2160 net/wireless/core.c:562 ieee80211_alloc_hw_nm+0x1b7a/0x2260 net/mac80211/main.c:835 mac80211_hwsim_new_radio+0x1d6/0x54e0 drivers/net/wireless/virtual/mac80211_hwsim.c:5185 hwsim_new_radio_nl+0xb42/0x12b0 drivers/net/wireless/virtual/mac80211_hwsim.c:6242 genl_family_rcv_ms

Affected

25 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 0272d4af7f92997541d8bbf4c51918b93ded6ee2 < b679fe84cd5cc6f3481b7131fd28676191ad2615b679fe84cd5cc6f3481b7131fd28676191ad2615
linuxlinux>= 6.1.132 < 6.1.1426.1.142
linuxlinux>= 6.12.20 < 6.12.356.12.35
linuxlinux>= 6.13.8 < 6.146.14
linuxlinux>= 6.6.84 < 6.6.956.6.95
linuxlinux>= 72d520476a2fab6f3489e8388ab524985d6c4b90 < 2617f60c3613ef105b8db2d514d2cac2a1836f7d2617f60c3613ef105b8db2d514d2cac2a1836f7d
linuxlinux>= 72d520476a2fab6f3489e8388ab524985d6c4b90 < fc88dee89d7b63eeb17699393eb659aadf9d9b7cfc88dee89d7b63eeb17699393eb659aadf9d9b7c
linuxlinux>= 75d262ad3c36d52852d764588fcd887f0fcd9138 < eeacfbab984200dcdcd68fcf4c6e91e2c6b38792eeacfbab984200dcdcd68fcf4c6e91e2c6b38792
linuxlinux>= 8930a3e1568cf534f86c8ed2def817c6d0528fc1 < 7e6040853f5b5f067a18c52286e676bc298fe6a27e6040853f5b5f067a18c52286e676bc298fe6a2
linuxlinux>= a5158d67bff06cb6fea31be39aeb319fd908ed8e < 60606efbf52582c0ab93e99789fddced6b47297a60606efbf52582c0ab93e99789fddced6b47297a
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.1.132 < 6.1.1426.1.142
linuxlinux_kernel>= 6.12.20 < 6.12.356.12.35
linuxlinux_kernel>= 6.13.8 < 6.146.14
linuxlinux_kernel>= 6.6.84 < 6.6.956.6.95

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.