PT-2025-37205 · Linux+5 · Linux Kernel+5
Published
2025-06-30
·
Updated
2026-04-20
·
CVE-2025-39746
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The Linux kernel contains a flaw within the ath10k driver where, in rare cases, the driver may lose connection with the PCIe bus. This can lead to system crashes during resuming due to watchdog timeouts. The issue occurs when WMI commands timeout and repeatedly attempt to restart the device. A threshold for consecutive restart failures has been implemented to identify unreliable hardware, and all ath10k operations are skipped if the threshold is exceeded to prevent system crashes. The fix involves atomic variables (
fail cont count and pending recovery) to manage the recovery mechanism.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Ath10K