PT-2025-33552 · Linux+3 · Linux Kernel+3
Syzbot
·
Published
2025-08-16
·
Updated
2025-12-15
·
CVE-2025-38509
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The Linux kernel contains a flaw within the mac80211 component where it does not reject Very High Throughput (VHT) operating mode notifications for unsupported channel widths. Specifically, 5 MHz and 10 MHz channel widths are invalid under the VHT specification. Accepting malformed notifications with these unsupported widths can lead to a warning due to invalid input within the
ieee80211 chan width to rx bw() function. The issue was reported by syzbot.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Ubuntu