CVE-2025-38294
Last modified
CVE-2025-38294 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL access in assign channel context handler Currently, when ath12k_mac_assign_vif_to_vdev() fails, the radio handle (ar) gets accessed from the link VIF handle (arvif) for debug logging, This is incorrect. In the fail scenario, radio handle is NULL. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix NULL access in assign channel context handler Currently, when ath12k_mac_assign_vif_to_vdev() fails, the radio handle (ar) gets accessed from the link VIF handle (arvif) for debug logging, This is incorrect. In the fail scenario, radio handle is NULL. Fix the NULL access, avoid radio handle access by moving to the hardware debug logging helper function (ath12k_hw_warn). Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.14, < 6.15.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-38294?
How severe is CVE-2025-38294?
How do I fix CVE-2025-38294?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-38289In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-3829A vulnerability was found in PHPGurukul Men Salon Management…9.8
- CVE-2025-38290In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38291In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38292In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-38293In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38295In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38296In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38297In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38298In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38299In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-3830A vulnerability was found in kuangstudy KuangSimpleBBS 1.0. …9.8
Are you affected by CVE-2025-38294?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
