CVE-2025-39918 — Improper Restriction of Operations within the Bounds of a Memory Buffer in Linux
Severity
5.5MEDIUMNVD
EPSS
0.0%
top 98.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 1
Description
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: fix linked list corruption
Never leave scheduled wcid entries on the temporary on-stack list
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
▶CVEListV5linux/linux0b3be9d1d34e21dada69c539fbf51a5fe868028a — e4d5a5fc61fdc65220a1ce078d24c1d20bbb0835+3
Patches
🔴Vulnerability Details
2GHSA▶
GHSA-64qw-p444-mx2m: In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: fix linked list corruption
Never leave scheduled wcid entries on the↗2025-10-01
OSV▶
CVE-2025-39918: In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: fix linked list corruption Never leave scheduled wcid entries on the t↗2025-10-01