PT-2025-37205 · Linux+5 · Linux Kernel+5

Published

2025-06-30

·

Updated

2026-04-20

·

CVE-2025-39746

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains a flaw within the ath10k driver where, in rare cases, the driver may lose connection with the PCIe bus. This can lead to system crashes during resuming due to watchdog timeouts. The issue occurs when WMI commands timeout and repeatedly attempt to restart the device. A threshold for consecutive restart failures has been implemented to identify unreliable hardware, and all ath10k operations are skipped if the threshold is exceeded to prevent system crashes. The fix involves atomic variables (fail cont count and pending recovery) to manage the recovery mechanism.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-67190
AZL-70813
BDU:2026-01376
CVE-2025-39746
ECHO-4EC2-4935-01DC
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03601-1
SUSE-SU-2025:03602-1
SUSE-SU-2025:03615-1
SUSE-SU-2025:03628-1
SUSE-SU-2025:03633-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3716-1
SUSE-SU-2025:3725-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:3761-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Ath10K