PT-2025-37219 · Linux+7 · Linux Kernel+7

Published

2025-05-26

·

Updated

2026-05-26

·

CVE-2025-39761

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The Linux kernel contains an issue in the ath12k driver related to handling RX peer fragmentation setup errors. Specifically, the Transmission Identifier (TID) is not decremented before peer cleanup during error handling in the ath12k dp rx peer frag setup() function. This can lead to out-of-bounds access within the peer->rx tid[] array. The issue was identified during a code review.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2025:17377
ALSA-2025:17776
BDU:2025-15698
CVE-2025-39761
ECHO-4506-A352-EE8B
INFSA-2025_17377
OPENSUSE-SU-2025:20081-1
RHSA-2025_17377
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Suse
Ubuntu