CVE-2025-27558Improper Validation of Integrity Check Value in Kernel

Severity
9.1CRITICALNVD
NVD7.8OSV3.5
EPSS
0.2%
top 63.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 21
Latest updateAug 16

Description

IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

debiandebian/linux< linux 6.1.147-1 (bookworm)
debiandebian/linux-6.1< linux 6.1.147-1 (bookworm)
NVDlinux/linux_kernel6.1.1076.1.146+4
Debianlinux/linux_kernel< 6.1.147-1+2

Also affects: Debian Linux 11.0

🔴Vulnerability Details

5
GHSA
GHSA-hxq3-8p4p-wv7w: In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This patch is a mitigation to prev2025-08-16
OSV
CVE-2025-38512: In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This patch is a mitigation to preven2025-08-16
Kernel
wifi: prevent A-MSDU attacks in mesh networks2025-06-16
GHSA
GHSA-hchj-55px-fgw7: IEEE P8022025-05-21
OSV
CVE-2025-27558: IEEE P8022025-05-21

📋Vendor Advisories

3
Red Hat
kernel: wifi: prevent A-MSDU attacks in mesh networks2025-08-16
Debian
CVE-2025-38512: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: preve...2025
Debian
CVE-2025-27558: linux - IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. I...2025