cbcvebase.
CVE-2025-38643
published 2025-08-22

CVE-2025-38643: In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() Callers of wdev_chandef()…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.4th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac() Callers of wdev_chandef() must hold the wiphy mutex. But the worker cfg80211_propagate_cac_done_wk() never takes the lock. Which triggers the warning below with the mesh_peer_connected_dfs test from hostapd and not (yet) released mac80211 code changes: WARNING: CPU: 0 PID: 495 at net/wireless/chan.c:1552 wdev_chandef+0x60/0x165 Modules linked in: CPU: 0 UID: 0 PID: 495 Comm: kworker/u4:2 Not tainted 6.14.0-rc5-wt-g03960e6f9d47 #33 13c287eeabfe1efea01c0bcc863723ab082e17cf Workqueue: cfg80211 cfg80211_propagate_cac_done_wk Stack: 00000000 00000001 ffffff00 6093267c 00000000 6002ec30 6d577c50 60037608 00000000 67e8d108 6063717b 00000000 Call Trace: [] ? _printk+0x0/0x98 [] show_stack+0x10e/0x11a [] ? _printk+0x0/0x98 [] dump_stack_lvl+0x71/0xb8 [] ? wdev_chandef+0x60/0x165 [] dump_stack+0x1e/0x20 [] __warn+0x101/0x20f [] warn_slowpath_fmt+0xe3/0x15d [] ? mark_lock.part.0+0x0/0x4ec [] ? __this_cpu_preempt_check+0x0/0x16 [] ? mark_held_locks+0x5a/0x6e [] ? warn_slowpath_fmt+0x0/0x15d [] ? unblock_signals+0x3a/0xe7 [] ? um_set_signals+0x2d/0x43 [] ? __this_cpu_preempt_check+0x0/0x16 [] ? lock_is_held_type+0x207/0x21f [] wdev_chandef+0x60/0x165 [] regulatory_propagate_dfs_state+0x247/0x43f [] ? um_set_signals+0x0/0x43 [] cfg80211_propagate_cac_done_wk+0x3a/0x4a [] process_scheduled_works+0x3bc/0x60e [] ? move_linked_works+0x4d/0x81 [] ? assign_work+0x0/0xaa [] worker_thread+0x220/0x2dc [] ? set_pf_worker+0x0/0x57 [] ? to_kthread+0x0/0x43 [] kthread+0x2d3/0x2e2 [] ? worker_thread+0x0/0x2dc [] ? calculate_sigpending+0x0/0x56 [] new_thread_handler+0x4a/0x64 irq event stamp: 614611 hardirqs last enabled at (614621): [] __up_console_sem+0x82/0xaf hardirqs last disabled at (614630): [] __up_console_sem+0x43/0xaf softirqs last enabled at (614268): [] __ieee80211_wake_queue+0x933/0x985 softirqs last disabled at (614266): [] __ieee80211_wake_queue

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < defe9ce121160788547e8e6ec4438ad8a14f40dddefe9ce121160788547e8e6ec4438ad8a14f40dd
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < b3d24038eb775f2f7a1dfef58d8e1dc444a12820b3d24038eb775f2f7a1dfef58d8e1dc444a12820
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < 4a63523d3541eef4cf504a9682e6fbe94ffe79a64a63523d3541eef4cf504a9682e6fbe94ffe79a6
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < 7022df2248c08c6f75a01714163ac902333bf3db7022df2248c08c6f75a01714163ac902333bf3db
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < dbce810607726408f889d3358f4780fd1436861edbce810607726408f889d3358f4780fd1436861e
linuxlinux>= 26ec17a1dc5ecdd8d91aba63ead6f8b5ad5dea0d < 2c5dee15239f3f3e31aa5c8808f18996c039e2c12c5dee15239f3f3e31aa5c8808f18996c039e2c1
linuxlinux>= 4.14.170 < 4.154.15
linuxlinux>= 4.19.102 < 4.204.20
linuxlinux>= 5.4.18 < 5.55.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 4.14.170 < 4.154.15
linuxlinux_kernel>= 4.19.102 < 4.204.20
linuxlinux_kernel>= 5.4.18 < 5.55.5
linuxlinux_kernel>= 5.5.1 < 6.6.1186.6.118

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.