In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: fix use-after-free in cmp_bss()
Following bssfree() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211updateknownbss() to free the last beacon frame elements only if they're not shared via the corresponding 'hiddenbeaconbss' pointer.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5b7ae04969f822283a95c866967e42b4d75e0eef",
"signature_version": "v1",
"id": "CVE-2025-39864-25011fad",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ff040562c10a540b8d851f7f4145fa112977f853",
"signature_version": "v1",
"id": "CVE-2025-39864-8b3f84e1",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b7d08929178c16398278613df07ad65cf63cce9d",
"signature_version": "v1",
"id": "CVE-2025-39864-9936fc57",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@26e84445f02ce6b2fe5f3e0e28ff7add77f35e08",
"signature_version": "v1",
"id": "CVE-2025-39864-a7d51f4a",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a97a9791e455bb0cd5e7a38b5abcb05523d4e21c",
"signature_version": "v1",
"id": "CVE-2025-39864-bd058bd6",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@912c4b66bef713a20775cfbf3b5e9bd71525c716",
"signature_version": "v1",
"id": "CVE-2025-39864-c4a8cbef",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a8bb681e879ca3c9f722aa08d3d7ae41c42a8807",
"signature_version": "v1",
"id": "CVE-2025-39864-c5b8c422",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"29827470451581928856182639531544635003",
"154589992789305034399103548880305224256",
"280770683331690272160291094316976816301",
"121107205534884560785820791278240142623"
]
},
"target": {
"file": "net/wireless/scan.c"
},
"signature_type": "Line",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@6854476d9e1aeaaf05ebc98d610061c2075db07d",
"signature_version": "v1",
"id": "CVE-2025-39864-f77609af",
"deprecated": false
}
]