Junglewise Threat Intelligence

CVE-2025-38601: Linux Kernel ath11k Wi-Fi driver kernel page fault in SRNG deinit

CVE-2025-38601 · Severity: high · CVSS 8.8 · Published 2025-08-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Qualcomm ath11k Wi-Fi driver can cause a system crash (kernel panic) during power management operations like resuming from sleep. This occurs when the driver fails to properly reset its internal state after a firmware crash, leading it to access invalid memory locations. A successful exploit could result in a complete system shutdown or denial of service for devices using these Wi-Fi chips.

Technical details

A vulnerability exists in the Linux kernel ath11k Wi-Fi driver due to missing initialization of resources in the ath11k_hal_srng_deinit() function. When the driver attempts to reconfigure after a firmware crash, it destroys SRNG (Static Ring) lists but fails to clear the 'initialized' flag. A subsequent call to ath11k_hal_dump_srng_stats() relies on this stale flag, leading to a supervisor read access page fault (NULL pointer dereference or use-after-free style access) and a kernel panic. The issue is triggered during crash recovery or system resume cycles. Patches have been released for various stable kernel branches to ensure the flag is cleared during de-initialization.

Affected products

  • Linux Linux Kernel ath11k driver

Timeline

  • 2025-06-12: patched: Initial patch submitted by Sergey Senozhatsky
  • 2025-08-19: advisory: CVE-2025-38601 published

References