CVE-2025-6592
published 2026-02-02CVE-2025-6592: Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects…
PriorityP411low2.1CVSS 4.0
AVNACLATPPRHUINVCLVINVANSCLSINSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.36%
28.5th percentile
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php.
This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mediawiki | < mediawiki 1:1.43.3+dfsg-1 (forky) | mediawiki 1:1.43.3+dfsg-1 (forky) |
| mediawiki | mediawiki | >= 0 < 1:1.43.3+dfsg-1 | 1:1.43.3+dfsg-1 |
| mediawiki | mediawiki | >= 0 < 1:1.43.3+dfsg-1 | 1:1.43.3+dfsg-1 |
| wikimedia_foundation | abusefilter | >= fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 < 1.43.2, 1.44.0 | 1.43.2, 1.44.0 |
CVSS provenance
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.1LOW
vendor_redhat7.8HIGH
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: btrfs: fix assertion when building free space tree
vendor_redhat·2025-08-16·CVSS 5.5
CVE-2025-38503 [MEDIUM] CWE-253 kernel: btrfs: fix assertion when building free space tree
kernel: btrfs: fix assertion when building free space tree
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix assertion when building free space tree
When building the free space tree with the block group tree feature
enabled, we can hit an assertion failure like this:
BTRFS info (device loop0 state M): rebuilding free space tree
assertion failed: ret == 0, in fs/btrfs/free-space-tree.c:1102
------------[ cut here ]------------
kernel BUG at fs/btrfs/free-space-tree.c:1102!
Internal error: Oops - BUG: 00000000f2000800 [#1] SMP
Modules linked in:
CPU: 1 UID: 0 PID: 6592 Comm: syz-executor322 Not tainted 6.15.0-rc7-syzkaller-gd7fa1af5b33e #0 PREEMPT
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025
pstate: 60400005 (nZCv da
Red Hat
kernel: net: drv: netdevsim: don't napi_complete() from netpoll
vendor_redhat·2025-07-10·CVSS 7.8
CVE-2025-38270 [HIGH] CWE-672 kernel: net: drv: netdevsim: don't napi_complete() from netpoll
kernel: net: drv: netdevsim: don't napi_complete() from netpoll
In the Linux kernel, the following vulnerability has been resolved:
net: drv: netdevsim: don't napi_complete() from netpoll
netdevsim supports netpoll. Make sure we don't call napi_complete()
from it, since it may not be scheduled. Breno reports hitting a
warning in napi_complete_done():
WARNING: CPU: 14 PID: 104 at net/core/dev.c:6592 napi_complete_done+0x2cc/0x560
__napi_poll+0x2d8/0x3a0
handle_softirqs+0x1fe/0x710
This is presumably after netpoll stole the SCHED bit prematurely.
Statement: A missing check in the netdevsim NAPI poll function could lead to a warning or soft crash when used with netpoll, due to premature calls to napi_complete() without verifying scheduling state. This issue is mitigated by replacing the cal
Debian
CVE-2025-6592: mediawiki - Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associa...
vendor_debian·2025·CVSS 2.1
CVE-2025-6592 [LOW] CVE-2025-6592: mediawiki - Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associa...
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:1.43.3+dfsg-1)
sid: resolved (fixed in 1:1.43.3+dfsg-1)
trixie: resolved (fixed in 1:1.43.3+dfsg-1)
GHSA
GHSA-9r44-56w8-gqrx: Vulnerability in Wikimedia Foundation AbuseFilter
ghsa_unreviewed·2026-02-03
CVE-2025-6592 [LOW] CWE-284 GHSA-9r44-56w8-gqrx: Vulnerability in Wikimedia Foundation AbuseFilter
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php.
This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.
OSV
CVE-2025-6592: Vulnerability in Wikimedia Foundation AbuseFilter
osv·2026-02-02·CVSS 2.1
CVE-2025-6592 [LOW] CVE-2025-6592: Vulnerability in Wikimedia Foundation AbuseFilter
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php. This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-6592 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 2.1
CVE-2025-6592 [LOW] CVE-2025-6592 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-6592 :
Linux Debian vulnerability analysis and mitigation
Vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/auth/AuthManager.Php.
This issue affects AbuseFilter: from fe0b1cb9e9691faf4d8d9bd80646589f6ec37615 before 1.43.2, 1.44.0.
Source : NVD
## 2.1
Score
Published February 2, 2026
Severity LOW
CNA Score 2.1
Affected Technologies
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 3.8
Exploitation Probability (EPSS) N/A
Affected packages and libraries
mediawiki
Sources
NVD
Debian 13 Has Fix Added at: Jul 03, 2025
Debian 14 Has Fix Added at: Aug 10, 2025
## Get a CVE risk assessment
Get a pri
Bugzilla
CVE-2025-38270 kernel: net: drv: netdevsim: don't napi_complete() from netpoll
bugzilla·2025-07-10·CVSS 7.8
CVE-2025-38270 [HIGH] CVE-2025-38270 kernel: net: drv: netdevsim: don't napi_complete() from netpoll
CVE-2025-38270 kernel: net: drv: netdevsim: don't napi_complete() from netpoll
In the Linux kernel, the following vulnerability has been resolved:
net: drv: netdevsim: don't napi_complete() from netpoll
netdevsim supports netpoll. Make sure we don't call napi_complete()
from it, since it may not be scheduled. Breno reports hitting a
warning in napi_complete_done():
WARNING: CPU: 14 PID: 104 at net/core/dev.c:6592 napi_complete_done+0x2cc/0x560
__napi_poll+0x2d8/0x3a0
handle_softirqs+0x1fe/0x710
This is presumably after netpoll stole the SCHED bit prematurely.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025071008-CVE-2025-38270-c7b0@gregkh/T
2026-02-02
Published