cbcvebase.
CVE-2025-39957
published 2025-10-09

CVE-2025-39957: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
4.1th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: increase scan_ies_len for S1G Currently the S1G capability element is not taken into account for the scan_ies_len, which leads to a buffer length validation failure in ieee80211_prep_hw_scan() and subsequent WARN in __ieee80211_start_scan(). This prevents hw scanning from functioning. To fix ensure we accommodate for the S1G capability length.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux>= 0333a81bc83431d7f90391d38aa09e856c5e5b25 < 93e063f15e17acb8cd6ac90c8f0802c2624e1a7493e063f15e17acb8cd6ac90c8f0802c2624e1a74
linuxlinux>= 0333a81bc83431d7f90391d38aa09e856c5e5b25 < 32adb020b0c32939da1322dcc87fc0ae2bc935d132adb020b0c32939da1322dcc87fc0ae2bc935d1
linuxlinux>= 0333a81bc83431d7f90391d38aa09e856c5e5b25 < 0dbad5f5549e54ac269cc04ce89f212892a98cab0dbad5f5549e54ac269cc04ce89f212892a98cab
linuxlinux>= 0333a81bc83431d7f90391d38aa09e856c5e5b25 < 7e2f3213e85eba00acb4cfe6d71647892d63c3a17e2f3213e85eba00acb4cfe6d71647892d63c3a1
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.9-16.16.9-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13 < 6.16.96.16.9
linuxlinux_kernel>= 6.4 < 6.6.1086.6.108
linuxlinux_kernel>= 6.7 < 6.12.496.12.49
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.