CVE-2025-37943

HIGH

Linux Kernel 6.3-6.6.87, 6.7-6.12.23, 6.13-6.13.11, 6.14-6.14.2 - Out-of-bounds Write in ath12k_dp_rx_h_undecap_nwifi

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1

Scores

CVSS v3 7.8
EPSS 0.0017
EPSS Percentile 6.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (17)
linux/Kernel 6.13.0 - 6.13.12linux
linux/Kernel 6.14.0 - 6.14.3linux
linux/Kernel 6.3.0 - 6.6.88linux
linux/Kernel 6.7.0 - 6.12.24linux
Linux/Linux < 6.3
Linux/Linux 6.12.24 - 6.12.*
Linux/Linux 6.13.12 - 6.13.*
Linux/Linux 6.14.3 - 6.14.*
Linux/Linux 6.15
Linux/Linux 6.3
... and 7 more
Published May 20, 2025
Tracked Since Feb 18, 2026