CVE-2025-39864

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-39864
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-39864.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-39864
Downstream
Related
Published
2025-09-19T15:26:33.787Z
Modified
2025-11-28T02:35:24.107270Z
Summary
wifi: cfg80211: fix use-after-free in cmp_bss()
Details

In the Linux kernel, the following vulnerability has been resolved:

wifi: cfg80211: fix use-after-free in cmp_bss()

Following bssfree() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211updateknownbss() to free the last beacon frame elements only if they're not shared via the corresponding 'hiddenbeaconbss' pointer.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39864.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6
Fixed
a8bb681e879ca3c9f722aa08d3d7ae41c42a8807
Fixed
a97a9791e455bb0cd5e7a38b5abcb05523d4e21c
Fixed
ff040562c10a540b8d851f7f4145fa112977f853
Fixed
6854476d9e1aeaaf05ebc98d610061c2075db07d
Fixed
b7d08929178c16398278613df07ad65cf63cce9d
Fixed
5b7ae04969f822283a95c866967e42b4d75e0eef
Fixed
912c4b66bef713a20775cfbf3b5e9bd71525c716
Fixed
26e84445f02ce6b2fe5f3e0e28ff7add77f35e08

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.4.0
Fixed
5.4.299
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.243
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.192
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.151
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.105
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.46
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.16.6