CVE-2025-39862Out-of-bounds Write in Linux

Severity
7.8HIGHNVD
EPSS
0.0%
top 94.20%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 19
Latest updateSep 22

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are recreated from scratch, all lists that wcids are added to must be cleared before calling ieee80211_restart_hw. Set wcid->sta = 0 for each wcid entry in order to ensure that they are not added again before they are ready.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-89h6-xrm9-52q6: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations ar2025-09-22
OSV
CVE-2025-39862: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7915: fix list corruption after hardware restart Since stations are2025-09-19

📋Vendor Advisories

3
Red Hat
kernel: wifi: mt76: mt7915: fix list corruption after hardware restart2025-09-19
Microsoft
wifi: mt76: mt7915: fix list corruption after hardware restart2025-09-09
Debian
CVE-2025-39862: linux - In the Linux kernel, the following vulnerability has been resolved: wifi: mt76:...2025
CVE-2025-39862 — Out-of-bounds Write in Linux | cvebase