CVE-2025-38157

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38157
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38157.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38157
Downstream
Related
Published
2025-07-03T09:15:30Z
Modified
2025-08-12T21:01:39Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath9k_htc: Abort software beacon handling if disabled

A malicious USB device can send a WMISWBAEVENTID event from an ath9k_htc-managed device before beaconing has been enabled. This causes a device-by-zero error in the driver, leading to either a crash or an out of bounds read.

Prevent this by aborting the handling in ath9khtcswba() if beacons are not enabled.

References

Affected packages