CVE-2025-38294

MEDIUM

Linux Kernel 6.14-6.15.3 - NULL Pointer Dereference in ath12k_mac_assign_vif_to_vdev

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL access in assign channel context handler Currently, when ath12k_mac_assign_vif_to_vdev() fails, the radio handle (ar) gets accessed from the link VIF handle (arvif) for debug logging, This is incorrect. In the fail scenario, radio handle is NULL. Fix the NULL access, avoid radio handle access by moving to the hardware debug logging helper function (ath12k_hw_warn). Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (8)
linux/Kernel 6.14.0 - 6.15.3linux
Linux/Linux < 6.14
Linux/Linux 6.14
Linux/Linux 6.15.3 - 6.15.*
Linux/Linux 6.16
Linux/Linux 90570ba4610bdb1db39ef45f2b271a9f89680a9d - 3f919f76893069ec3c7475acaeb611eb31fca22d
Linux/Linux 90570ba4610bdb1db39ef45f2b271a9f89680a9d - ea24531d00f782f4e659e8c74578b7ac144720ca
linux/linux_kernel 6.14 - 6.15.3
Published Jul 10, 2025
Tracked Since Feb 18, 2026