PT-2025-40065 · Linux+5 · Linux Kernel+5
Published
2025-01-01
·
Updated
2026-05-07
·
CVE-2025-39891
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The
adapter->chan stats[] array within the mwifiex module is not properly initialized to zero, potentially leading to an information leak. The array is allocated using vmalloc(), which does not zero out the memory. This can occur if mwifiex cfg80211 dump survey() is called before the data is populated by mwifiex update chan statistics(), or if mwifiex update chan statistics() does not initialize the entire array. The chan stats array is used to store channel statistics and is accessed through the mwifiex cfg80211 dump survey() function.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Mwifiex