PT-2025-40648 · Linux+4 · Linux Kernel+4
Published
2025-10-04
·
Updated
2026-05-07
·
CVE-2025-39952
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A buffer overflow issue exists in the wilc1000 driver related to WID string configuration. The problem occurs during the parsing of response frames, specifically when copying data into the
cfg->s[i]->str buffer. A size check has been added to prevent the overflow, based on the WID type received from the firmware and the size limits defined in the wilc cfg str vals structure. The vulnerable function is wilc wlan parse response frame().Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu