PT-2025-40065 · Linux+5 · Linux Kernel+5

Published

2025-01-01

·

Updated

2026-05-07

·

CVE-2025-39891

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The adapter->chan stats[] array within the mwifiex module is not properly initialized to zero, potentially leading to an information leak. The array is allocated using vmalloc(), which does not zero out the memory. This can occur if mwifiex cfg80211 dump survey() is called before the data is populated by mwifiex update chan statistics(), or if mwifiex update chan statistics() does not initialize the entire array. The chan stats array is used to store channel statistics and is accessed through the mwifiex cfg80211 dump survey() function.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

AZL-68007
AZL-75122
BDU:2025-15674
CVE-2025-39891
DLA-4327-1
DLA-4328-1
ECHO-FF8D-1332-73FA
OPENSUSE-SU-2025:20081-1
SUSE-SU-2025:03600-1
SUSE-SU-2025:03634-1
SUSE-SU-2025:20851-1
SUSE-SU-2025:20861-1
SUSE-SU-2025:20870-1
SUSE-SU-2025:20898-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025:3751-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4141-1
USN-7909-1
USN-7909-2
USN-7909-3
USN-7909-4
USN-7909-5
USN-7910-1
USN-7910-2
USN-7933-1
USN-7938-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Suse
Ubuntu
Mwifiex