cbcvebase.
CVE-2025-68729
published 2025-12-24

CVE-2025-68729: In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix MSDU buffer types handling in RX error path Currently, packets received…

PriorityP421high7.2
EPSS
0.16%
5.8th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix MSDU buffer types handling in RX error path Currently, packets received on the REO exception ring from unassociated peers are of MSDU buffer type, while the driver expects link descriptor type packets. These packets are not parsed further due to a return check on packet type in ath12k_hal_desc_reo_parse_err(), but the associated skb is not freed. This may lead to kernel crashes and buffer leaks. Hence to fix, update the RX error handler to explicitly drop MSDU buffer type packets received on the REO exception ring. This prevents further processing of invalid packets and ensures stability in the RX error handling path. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.13-1 (forky)linux 6.17.13-1 (forky)
linuxlinux
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 5ff5a9d71cdc49c3400f30583a784ad0a17d01ec5ff5a9d71cdc49c3400f30583a784ad0a17d01ec
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < ab0554f51e5f2b9506e8a09e8accd02f00056729ab0554f51e5f2b9506e8a09e8accd02f00056729
linuxlinux>= d889913205cf7ebda905b1e62c5867ed4e39f6c2 < 36f9edbb9d0fc36c865c74f3c1ad8e1261ad398136f9edbb9d0fc36c865c74f3c1ad8e1261ad3981
linuxlinux_kernel>= 0 < 6.17.13-16.17.13-1
linuxlinux_kernel>= 0 < 6.17.0-19.196.17.0-19.19
linuxlinux_kernel>= 6.18.0 < 6.18.26.18.2
linuxlinux_kernel>= 6.3.0 < 6.17.136.17.13
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0

CVSS provenance

osv7.2HIGH
vendor_ubuntu7.2HIGH
vendor_msrc7.0HIGH
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.