CVE-2025-38406

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at this point etc., so the WARN_ON() doesn't add any value. Additionally, this is one of the top syzbot reports now. Just print a message, and as an added bonus, print the sizes too.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

23 Dec 2025, 19:45

Type Values Removed Values Added
First Time Linux
Debian
Debian debian Linux
Linux linux Kernel
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
References () https://git.kernel.org/stable/c/27d07deea35ae67f2e75913242e25bdb7e1114e5 - () https://git.kernel.org/stable/c/27d07deea35ae67f2e75913242e25bdb7e1114e5 - Patch
References () https://git.kernel.org/stable/c/327997afbb5e62532c28c1861ab5534c01969c9a - () https://git.kernel.org/stable/c/327997afbb5e62532c28c1861ab5534c01969c9a - Patch
References () https://git.kernel.org/stable/c/347827bd0c5680dac2dd59674616840c4d5154f1 - () https://git.kernel.org/stable/c/347827bd0c5680dac2dd59674616840c4d5154f1 - Patch
References () https://git.kernel.org/stable/c/46b47d4b06fa7f234d93f0f8ac43798feafcff89 - () https://git.kernel.org/stable/c/46b47d4b06fa7f234d93f0f8ac43798feafcff89 - Patch
References () https://git.kernel.org/stable/c/7a2afdc5af3b82b601f6a2f0d1c90d5f0bc27aeb - () https://git.kernel.org/stable/c/7a2afdc5af3b82b601f6a2f0d1c90d5f0bc27aeb - Patch
References () https://git.kernel.org/stable/c/89bd133529a4d2d68287128b357e49adc00ec690 - () https://git.kernel.org/stable/c/89bd133529a4d2d68287128b357e49adc00ec690 - Patch
References () https://git.kernel.org/stable/c/e6c49f0b203a987c306676d241066451b74db1a5 - () https://git.kernel.org/stable/c/e6c49f0b203a987c306676d241066451b74db1a5 - Patch
References () https://git.kernel.org/stable/c/e7417421d89358da071fd2930f91e67c7128fbff - () https://git.kernel.org/stable/c/e7417421d89358da071fd2930f91e67c7128fbff - Patch
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html - Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html - Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

03 Nov 2025, 18:16

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html -
  • () https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html -
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: wifi: ath6kl: eliminar WARN sobre entrada de firmware incorrecta. Si el firmware genera una entrada incorrecta, no tiene nada que ver con la pila del controlador en este momento, etc., por lo que WARN_ON() no aporta ningún valor. Además, este es uno de los principales reportes de syzbot. Simplemente imprime un mensaje y, como extra, también imprime los tamaños.

25 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-25 14:15

Updated : 2025-12-23 19:45


NVD link : CVE-2025-38406

Mitre link : CVE-2025-38406

CVE.ORG link : CVE-2025-38406


JSON object : View

Products Affected

debian

  • debian_linux

linux

  • linux_kernel