cbcvebase.
CVE-2025-39991
published 2025-10-15

CVE-2025-39991: In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to…

PriorityP420high7.8
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.11-1 (forky)linux 6.16.11-1 (forky)
linuxlinux
linuxlinux>= 7db88b962f06a52af5e9a32971012e8f3427cec0 < 1f52119809b76d43759fc47da1cf708690b740a11f52119809b76d43759fc47da1cf708690b740a1
linuxlinux>= 7db88b962f06a52af5e9a32971012e8f3427cec0 < 888830b2cbc035838bebefe94502976da94332a5888830b2cbc035838bebefe94502976da94332a5
linuxlinux>= 7db88b962f06a52af5e9a32971012e8f3427cec0 < 500fcc31e488d798937a23dbb1f62db46820c5b2500fcc31e488d798937a23dbb1f62db46820c5b2
linuxlinux>= 7db88b962f06a52af5e9a32971012e8f3427cec0 < 3fd2ef2ae2b5c955584a3bee8e83ae7d7a98f7823fd2ef2ae2b5c955584a3bee8e83ae7d7a98f782
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.11-16.16.11-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 6.13.0 < 6.16.116.16.11
linuxlinux_kernel>= 6.17.0 < 6.17.16.17.1
linuxlinux_kernel>= 6.7.0 < 6.12.516.12.51
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
vendor_redhat4.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.