cbcvebase.
CVE-2025-71224
published 2026-02-14

CVE-2025-71224: In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface is not joined ieee80211_ocb_rx_no_sta()…

PriorityP420high7.8
EPSS
0.17%
7.0th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: ocb: skip rx_no_sta when interface is not joined ieee80211_ocb_rx_no_sta() assumes a valid channel context, which is only present after JOIN_OCB. RX may run before JOIN_OCB is executed, in which case the OCB interface is not operational. Skip RX peer handling when the interface is not joined to avoid warnings in the RX path.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < fcc768760df08337525cde28e8460e36f9855af8fcc768760df08337525cde28e8460e36f9855af8
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < b04c75366a5471ae2dd7f4c33b7f1e2c08b9b32db04c75366a5471ae2dd7f4c33b7f1e2c08b9b32d
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < 8fd1c63e016893b7f6c1cf799410da4eaa98c0908fd1c63e016893b7f6c1cf799410da4eaa98c090
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < ffe1e19c3b0e5b9eb9e04fad4bce7d1dc407fd77ffe1e19c3b0e5b9eb9e04fad4bce7d1dc407fd77
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < 536447521b3b9be1975c7f1db9054bdf2ab779cb536447521b3b9be1975c7f1db9054bdf2ab779cb
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < e0bd226804f8e0098711042c93d64f3b720b36c0e0bd226804f8e0098711042c93d64f3b720b36c0
linuxlinux>= 239281f803e2efdb77d906ef296086b6917e5d71 < ff4071c60018a668249dc6a2df7d16330543540eff4071c60018a668249dc6a2df7d16330543540e
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.10-16.18.10-1
linuxlinux_kernel>= 3.19.0 < 5.10.2505.10.250
linuxlinux_kernel>= 5.11.0 < 5.15.2005.15.200
linuxlinux_kernel>= 5.16.0 < 6.1.1636.1.163
linuxlinux_kernel>= 6.13.0 < 6.18.106.18.10
linuxlinux_kernel>= 6.2.0 < 6.6.1246.6.124
linuxlinux_kernel>= 6.7.0 < 6.12.706.12.70
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure

CVSS provenance

vendor_ubuntu7.8HIGH
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.