cbcvebase.
CVE-2025-38157
published 2025-07-03

CVE-2025-38157: In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: Abort software beacon handling if disabled A malicious USB device can send…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: Abort software beacon handling if disabled A malicious USB device can send a WMI_SWBA_EVENTID event from an ath9k_htc-managed device before beaconing has been enabled. This causes a device-by-zero error in the driver, leading to either a crash or an out of bounds read. Prevent this by aborting the handling in ath9k_htc_swba() if beacons are not enabled.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < e5ce9df1d68094d37360dbd9b09289d42fa21e54e5ce9df1d68094d37360dbd9b09289d42fa21e54
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < 0281c19074976ec48f0078d50530b406ddae75bc0281c19074976ec48f0078d50530b406ddae75bc
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < 7ee3fb6258da8c890a51b514f60d7570dc7036057ee3fb6258da8c890a51b514f60d7570dc703605
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < 40471b23147c86ea3ed97faee79937c618250bd040471b23147c86ea3ed97faee79937c618250bd0
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < 5482ef9875eaa43f0435e14570e1193823de857e5482ef9875eaa43f0435e14570e1193823de857e
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < ee5ee646385f5846dcbc881389f3c44a197c402aee5ee646385f5846dcbc881389f3c44a197c402a
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < 5a85c21f812e02cb00ca07007d88acdd42d08c465a85c21f812e02cb00ca07007d88acdd42d08c46
linuxlinux>= 832f6a18fc2aead14954c081ece03b7a5b425f81 < ac4e317a95a1092b5da5b9918b7118759342641cac4e317a95a1092b5da5b9918b7118759342641c
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 3.0 < 5.4.2955.4.295
linuxlinux_kernel>= 5.11 < 5.15.1865.15.186
linuxlinux_kernel>= 5.16 < 6.1.1426.1.142
linuxlinux_kernel>= 5.5 < 5.10.2395.10.239
linuxlinux_kernel>= 6.13 < 6.15.36.15.3
linuxlinux_kernel>= 6.2 < 6.6.946.6.94
linuxlinux_kernel>= 6.7 < 6.12.346.12.34

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH