CVE-2025-68380
Last modified
CVE-2025-68380 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix peer HE MCS assignment In ath11k_wmi_send_peer_assoc_cmd(), peer's transmit MCS is sent to firmware as receive MCS while peer's receive MCS sent as transmit MCS, which goes against firmwire's definition. While connecting to a misbehaved AP that advertises 0xffff (meaning not supported) for 160 MHz transmit MCS map, firmware crashes due to 0xffff is assigned to he_mcs->rx_mcs_set field. Ext Tag: HE Capabilities [...] Supported HE-MCS and NSS Set [...] Rx and Tx MCS Maps 160 MHz [...] Tx HE-MCS Map 160 MHz: 0xffff Swap the assignment to fix this issue. As the HE rate control mask is meant to limit our own transmit MCS, it needs to go via he_mcs->rx_mcs_set field. With the aforementioned swapping done, change is needed as well to apply it to the peer's receive MCS. Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41 Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix peer HE MCS assignment In ath11k_wmi_send_peer_assoc_cmd(), peer's transmit MCS is sent to firmware as receive MCS while peer's receive MCS sent as transmit MCS, which goes against firmwire's definition. While connecting to a misbehaved AP that advertises 0xffff (meaning not supported) for 160 MHz transmit MCS map, firmware crashes due to 0xffff is assigned to he_mcs->rx_mcs_set field. Ext Tag: HE Capabilities [...] Supported HE-MCS and NSS Set [...] Rx and Tx MCS Maps 160 MHz [...] Tx HE-MCS Map 160 MHz: 0xffff Swap the assignment to fix this issue. As the HE rate control mask is meant to limit our own transmit MCS, it needs to go via he_mcs->rx_mcs_set field. With the aforementioned swapping done, change is needed as well to apply it to the peer's receive MCS. Tested-on: WCN6855 hw2.1 PCI WLAN.HSP.1.1-03125-QCAHSPSWPL_V1_V2_SILICONZ_LITE-3.6510.41 Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 92791290e4f6a1de25d35af792ab8918a70737f6; >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 4304bd7a334e981f189b9973056a58f84cc2b482; >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 097c870b91817779e5a312c6539099a884b1fe2b; >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 381096a417b7019896e93e86f4c585c592bf98e2; >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 6b1a0da75932353f66e710976ca85a7131f647ff; >= 61fe43e7216df6e9a912d831aafc7142fa20f280, < 4a013ca2d490c73c40588d62712ffaa432046a04 |
| Linux | Linux | 5.16 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-68380?
How severe is CVE-2025-68380?
How do I fix CVE-2025-68380?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-68375In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68376In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68377In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68378In the Linux kernel, the following vulnerability has been re…
- CVE-2025-68379In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-6838The Broken Link Notifier plugin for WordPress is vulnerable …4.1
- CVE-2025-68381Improper Bounds Check (CWE-787) in Packetbeat can allow a re…6.5
- CVE-2025-68382Out-of-bounds read (CWE-125) allows an unauthenticated remot…6.5
- CVE-2025-68383Improper Validation of Specified Index, Position, or Offset …6.5
- CVE-2025-68384Allocation of Resources Without Limits or Throttling (CWE-77…6.5
- CVE-2025-68385Improper neutralization of input during web page generation …6.1
- CVE-2025-68386Improper Authorization (CWE-285) in Kibana can lead to privi…4.3
Are you affected by CVE-2025-68380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
