cbcvebase.
CVE-2025-37794
published 2025-05-01

CVE-2025-37794: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Purge vif txq in ieee80211_do_stop() After ieee80211_do_stop() SKB from…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Purge vif txq in ieee80211_do_stop() After ieee80211_do_stop() SKB from vif's txq could still be processed. Indeed another concurrent vif schedule_and_wake_txq call could cause those packets to be dequeued (see ieee80211_handle_wake_tx_queue()) without checking the sdata current state. Because vif.drv_priv is now cleared in this function, this could lead to driver crash. For example in ath12k, ahvif is store in vif.drv_priv. Thus if ath12k_mac_op_tx() is called after ieee80211_do_stop(), ahvif->ah can be NULL, leading the ath12k_warn(ahvif->ah,...) call in this function to trigger the NULL deref below. Unable to handle kernel paging request at virtual address dfffffc000000001 KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] batman_adv: bat0: Interface deactivated: brbh1337 Mem abort info: ESR = 0x0000000096000004 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x04: level 0 translation fault Data abort info: ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 [dfffffc000000001] address between user and kernel address ranges Internal error: Oops: 0000000096000004 [#1] SMP CPU: 1 UID: 0 PID: 978 Comm: lbd Not tainted 6.13.0-g633f875b8f1e #114 Hardware name: HW (DT) pstate: 10000005 (nzcV daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : ath12k_mac_op_tx+0x6cc/0x29b8 [ath12k] lr : ath12k_mac_op_tx+0x174/0x29b8 [ath12k] sp : ffffffc086ace450 x29: ffffffc086ace450 x28: 0000000000000000 x27: 1ffffff810d59ca4 x26: ffffff801d05f7c0 x25: 0000000000000000 x24: 000000004000001e x23: ffffff8009ce4926 x22: ffffff801f9c0800 x21: ffffff801d05f7f0 x20: ffffff8034a19f40 x19: 0000000000000000 x18: ffffff801f9c0958 x17: ffffff800bc0a504 x16: dfffffc000000000 x15: ffffffc086ace4f8 x14: ffffff801d05f83c x13: 0000000000000000 x12: ffffffb003a0bf03 x11: 0000000000000000 x10

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < 929ec2c9ad34248ef625e137b6118b6e965797d9929ec2c9ad34248ef625e137b6118b6e965797d9
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < a932a5ce4eee0cbad20220f950fe7bd3534bcbc9a932a5ce4eee0cbad20220f950fe7bd3534bcbc9
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < 305741e7e63234cbcf9b5c4e6aeca25ba0834be8305741e7e63234cbcf9b5c4e6aeca25ba0834be8
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < 5f6863dc407f25fcf23fc857f9ac51756a09ea2c5f6863dc407f25fcf23fc857f9ac51756a09ea2c
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < c74b84544dee27298a71715b3ce2c40d372b5a23c74b84544dee27298a71715b3ce2c40d372b5a23
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < a8df245b5b29f6de98d016dc18e2bb35ec70b0cba8df245b5b29f6de98d016dc18e2bb35ec70b0cb
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < 8bc34db7f771a464ff8f686b6f8d4e04963fec278bc34db7f771a464ff8f686b6f8d4e04963fec27
linuxlinux>= ba8c3d6f16a1f9305c23ac1d2fd3992508c5ac03 < 378677eb8f44621ecc9ce659f7af61e5baa94d81378677eb8f44621ecc9ce659f7af61e5baa94d81
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.1 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.14.46.14.4
linuxlinux_kernel>= 6.2 < 6.6.886.6.88

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.