CVE-2025-39991
Published: October 17, 2025Last modified: June 24, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load() If ab->fw.m3_data points to data, then fw pointer remains null. Further, if m3_mem is not allocated, then fw is dereferenced to be passed to ath11k_err function. Replace fw->size by m3_len. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | linux-lts | Not affected (6.1.33-r0) |
| 25 LTS | linux-lts | Fixed (6.12.51-r0) | |
| Stream | linux-lts | Fixed (6.18.35-r1) |
References
- https://git.kernel.org/stable/c/1f52119809b76d43759fc47da1cf708690b740a1
- https://git.kernel.org/stable/c/3fd2ef2ae2b5c955584a3bee8e83ae7d7a98f782
- https://git.kernel.org/stable/c/500fcc31e488d798937a23dbb1f62db46820c5b2
- https://git.kernel.org/stable/c/7554d498e4283c3b4559795abd175eb24a84f47f
- https://git.kernel.org/stable/c/888830b2cbc035838bebefe94502976da94332a5