PT-2025-34407 · Rtw89+6 · Rtw89+6
Published
2025-06-18
·
Updated
2026-04-20
·
CVE-2025-38646
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel versions 6.6.56-05896-g89f5fb0eb30b and earlier.
Description:
A NULL dereference issue existed in the Linux kernel's
rtw89 driver related to Wi-Fi functionality. Specifically, a problematic packet received on an unsupported 6 GHz band could lead to a NULL dereference in the rtw89 vif rx stats iter() and rtw89 core cancel 6ghz probe tx() functions. This occurred when the system incorrectly identified a packet as being received on the 6 GHz band, even though the chip did not support it, resulting in a crash.Recommendations:
Linux kernel versions prior to 6.6.56-05896-g89f5fb0eb30b should be updated.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu
Rtw89