CVE-2025-38157

Updated: 2025-12-28 03:40:28.902042

Description:

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k_htc: Abort software beacon handling if disabled A malicious USB device can send a WMI_SWBA_EVENTID event from an ath9k_htc-managed device before beaconing has been enabled. This causes a device-by-zero error in the driver, leading to either a crash or an out of bounds read. Prevent this by aborting the handling in ath9k_htc_swba() if beacons are not enabled.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Needs Triage 2025-12-28 08:03:00
CentOS 7 ELS kernel 3.10.0 7.8 HIGH In Testing 2026-01-05 19:54:40
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:02:57
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:02:56
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Needs Triage 2025-12-28 08:03:04
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Needs Triage 2025-12-28 08:03:06
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2026:1767867153 2026-01-08 16:30:20
Oracle Linux 7 ELS kernel-uek 5.4.17 7.8 HIGH Released CLSA-2025:1757963029 2025-09-16 11:19:58
RHEL 7 ELS kernel 3.10.0 7.8 HIGH Released CLSA-2026:1767867718 2026-01-08 16:30:18
TuxCare 9.6 ESU kernel 5.14.0 7.8 HIGH Needs Triage 2025-12-28 08:02:58
Total: 14