cbcvebase.
CVE-2025-38013
published 2025-06-18

CVE-2025-38013: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Make sure that…

PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.17%
6.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Make sure that n_channels is set after allocating the struct cfg80211_registered_device::int_scan_req member. Seen with syzkaller: UBSAN: array-index-out-of-bounds in net/mac80211/scan.c:1208:5 index 0 is out of range for type 'struct ieee80211_channel *[] __counted_by(n_channels)' (aka 'struct ieee80211_channel *[]') This was missed in the initial conversions because I failed to locate the allocation likely due to the "sizeof(void *)" not matching the "channels" array type.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.30-1 (forky)linux 6.12.30-1 (forky)
linuxlinux
linuxlinux>= e3eac9f32ec04112b39e01b574ac739382469bf9 < fde33ab3c052a302ee8a0b739094b88ceae4dd67fde33ab3c052a302ee8a0b739094b88ceae4dd67
linuxlinux>= e3eac9f32ec04112b39e01b574ac739382469bf9 < 07c737d9ab02c07b562aefcca16aa95077368e2407c737d9ab02c07b562aefcca16aa95077368e24
linuxlinux>= e3eac9f32ec04112b39e01b574ac739382469bf9 < e3192e999a0d05ea0ba2c59c09afaf0b8ee70b81e3192e999a0d05ea0ba2c59c09afaf0b8ee70b81
linuxlinux>= e3eac9f32ec04112b39e01b574ac739382469bf9 < 82bbe02b2500ef0a62053fe2eb84773fe31c5a0a82bbe02b2500ef0a62053fe2eb84773fe31c5a0a
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.14.86.14.8
linuxlinux_kernel>= 6.6 < 6.6.926.6.92
linuxlinux_kernel>= 6.7 < 6.12.306.12.30
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.