CVE-2025-38420

Updated: 2025-12-28 03:43:19.853327

Description:

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: do not ping device which has failed to load firmware Syzkaller reports [1, 2] crashes caused by an attempts to ping the device which has failed to load firmware. Since such a device doesn't pass 'ieee80211_register_hw()', an internal workqueue managed by 'ieee80211_queue_work()' is not yet created and an attempt to queue work on it causes null-ptr-deref. [1] https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff [2] https://syzkaller.appspot.com/bug?extid=0d8afba53e8fb2633217


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-12-28 08:09:18
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:50 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:52 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:53 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Ignored 2026-01-17 01:05:50 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:48 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:49 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:19:38 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
RHEL 7 ELS kernel 3.10.0 5.5 MEDIUM Ignored 2026-01-17 01:05:48 This issue is confined to the legacy carl9170 USB Wi‑Fi driver and only triggers when an AR9170 ad...
TuxCare 9.6 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-12-28 08:09:17
Total: 14