CVE-2025-38420

Source
https://cve.org/CVERecord?id=CVE-2025-38420
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38420.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38420
Downstream
Related
Published
2025-07-25T14:16:41.479Z
Modified
2026-05-18T05:56:19.108242152Z
Summary
wifi: carl9170: do not ping device which has failed to load firmware
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: carl9170: do not ping device which has failed to load firmware

Syzkaller reports [1, 2] crashes caused by an attempts to ping the device which has failed to load firmware. Since such a device doesn't pass 'ieee80211registerhw()', an internal workqueue managed by 'ieee80211queuework()' is not yet created and an attempt to queue work on it causes null-ptr-deref.

[1] https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff [2] https://syzkaller.appspot.com/bug?extid=0d8afba53e8fb2633217

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38420.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
e4a668c59080f862af3ecc28b359533027cbe434
Fixed
0140d3d37f0f1759d1fdedd854c7875a86e15f8d
Fixed
8a3734a6f4c05fd24605148f21fb2066690d61b3
Fixed
527fad1ae32ffa2d4853a1425fe1c8dbb8c9744c
Fixed
bfeede26e97ce4a15a0b961118de4a0e28c9907a
Fixed
4e9ab5c48ad5153cc908dd29abad0cd2a92951e4
Fixed
301268dbaac8e9013719e162a000202eac8054be
Fixed
11ef72b3312752c2ff92f3c1e64912be3228ed36
Fixed
15d25307692312cec4b57052da73387f91a2e870

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38420.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.38
Fixed
5.4.295
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.142
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.95
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.35
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38420.json"