CVE-2025-38343

MEDIUM

Linux Kernel 6.2-6.6.95, 6.7-6.12.35, 6.13-6.15.4 - Denial of Service via Malformed WiFi Fragment

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: drop fragments with multicast or broadcast RA IEEE 802.11 fragmentation can only be applied to unicast frames. Therefore, drop fragments with multicast or broadcast RA. This patch addresses vulnerabilities such as CVE-2020-26145.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (14)
linux/Kernel 6.13.0 - 6.15.4linux
linux/Kernel 6.2.0 - 6.6.95linux
linux/Kernel 6.7.0 - 6.12.35linux
Linux/Linux < 6.2
Linux/Linux 6.12.35 - 6.12.*
Linux/Linux 6.15.4 - 6.15.*
Linux/Linux 6.16
Linux/Linux 6.2
Linux/Linux 6.6.95 - 6.6.*
Linux/Linux 98686cd21624c75a043e96812beadddf4f6f48e5 - 24900688ee47071aa6a61e78473999b5b80f0423
... and 4 more
Published Jul 10, 2025
Tracked Since Feb 18, 2026