cve/2025/CVE-2025-38157.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2025-38157

Description

In the Linux kernel, the following vulnerability has been resolved:wifi: ath9k_htc: Abort software beacon handling if disabledA malicious USB device can send a WMI_SWBA_EVENTID event from anath9k_htc-managed device before beaconing has been enabled. This causesa device-by-zero error in the driver, leading to either a crash or anout of bounds read.Prevent this by aborting the handling in ath9k_htc_swba() if beacons arenot enabled.

POC

Reference

No PoCs from references.

Github