cbcvebase.
CVE-2025-40321
published 2025-12-08

CVE-2025-40321: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode Currently…

PriorityP425high7.8
EPSS
0.18%
7.6th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode Currently, whenever there is a need to transmit an Action frame, the brcmfmac driver always uses the P2P vif to send the "actframe" IOVAR to firmware. The P2P interfaces were available when wpa_supplicant is managing the wlan interface. However, the P2P interfaces are not created/initialized when only hostapd is managing the wlan interface. And if hostapd receives an ANQP Query REQ Action frame even from an un-associated STA, the brcmfmac driver tries to use an uninitialized P2P vif pointer for sending the IOVAR to firmware. This NULL pointer dereferencing triggers a driver crash. [ 1417.074538] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000 [...] [ 1417.075188] Hardware name: Raspberry Pi 4 Model B Rev 1.5 (DT) [...] [ 1417.075653] Call trace: [ 1417.075662] brcmf_p2p_send_action_frame+0x23c/0xc58 [brcmfmac] [ 1417.075738] brcmf_cfg80211_mgmt_tx+0x304/0x5c0 [brcmfmac] [ 1417.075810] cfg80211_mlme_mgmt_tx+0x1b0/0x428 [cfg80211] [ 1417.076067] nl80211_tx_mgmt+0x238/0x388 [cfg80211] [ 1417.076281] genl_family_rcv_msg_doit+0xe0/0x158 [ 1417.076302] genl_rcv_msg+0x220/0x2a0 [ 1417.076317] netlink_rcv_skb+0x68/0x140 [ 1417.076330] genl_rcv+0x40/0x60 [ 1417.076343] netlink_unicast+0x330/0x3b8 [ 1417.076357] netlink_sendmsg+0x19c/0x3f8 [ 1417.076370] __sock_sendmsg+0x64/0xc0 [ 1417.076391] ____sys_sendmsg+0x268/0x2a0 [ 1417.076408] ___sys_sendmsg+0xb8/0x118 [ 1417.076427] __sys_sendmsg+0x90/0xf8 [ 1417.076445] __arm64_sys_sendmsg+0x2c/0x40 [ 1417.076465] invoke_syscall+0x50/0x120 [ 1417.076486] el0_svc_common.constprop.0+0x48/0xf0 [ 1417.076506] do_el0_svc+0x24/0x38 [ 1417.076525] el0_svc+0x30/0x100 [ 1417.076548] el0t_64_sync_handler+0x100/0x130 [ 1417.076569] el0t_64_sync+0x190/0x198 [ 1417.076589] Code: f9401e80 aa1603e2 f9403be1 5280e483 (f9400000) Fix this, by always using the vif cor

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
debianlinux-6.1< linux 6.1.159-1 (bookworm)linux 6.1.159-1 (bookworm)
linuxlinux
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < c863b9c7b4e9af0b7931cb791ec91971a50f1a25c863b9c7b4e9af0b7931cb791ec91971a50f1a25
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < e1fc9afcce9139791260f962541282d47fbb508de1fc9afcce9139791260f962541282d47fbb508d
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < 55f60a72a178909ece4e32987e4c642ba57e1cf455f60a72a178909ece4e32987e4c642ba57e1cf4
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < c2b0f8d3e7358c33d90f0e62765d474f25f26a45c2b0f8d3e7358c33d90f0e62765d474f25f26a45
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < 64e3175d1c8a3bea02032e7c9d1befd5f43786fa64e3175d1c8a3bea02032e7c9d1befd5f43786fa
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < a6eed58249e7d60f856900e682992300f770f64ba6eed58249e7d60f856900e682992300f770f64b
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < dbc7357b6aae686d9404e1dd7e2e6cf92c3a1b5adbc7357b6aae686d9404e1dd7e2e6cf92c3a1b5a
linuxlinux>= 18e2f61db3b708e0a22ccc403cb6ab2203d6faab < 3776c685ebe5f43e9060af06872661de55e80b9a3776c685ebe5f43e9060af06872661de55e80b9a
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.159-16.1.159-1
linuxlinux_kernel>= 0 < 6.12.63-16.12.63-1
linuxlinux_kernel>= 0 < 6.17.8-16.17.8-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 3.9.0 < 5.4.3025.4.302
linuxlinux_kernel>= 5.11.0 < 5.15.1975.15.197
linuxlinux_kernel>= 5.16.0 < 6.1.1596.1.159
linuxlinux_kernel>= 5.5.0 < 5.10.2475.10.247
linuxlinux_kernel>= 6.13.0 < 6.17.86.17.8
linuxlinux_kernel>= 6.2.0 < 6.6.1176.6.117
linuxlinux_kernel>= 6.7.0 < 6.12.586.12.58

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc6.5MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.