Executive brief
A vulnerability exists in the Linux kernel's wireless networking component (cfg80211) that could lead to system instability or unauthorized behavior. The issue occurs when the system handles specific Wi-Fi radar detection events without proper internal synchronization. An attacker within Wi-Fi range could potentially exploit this to cause a system crash or gain unauthorized control over the wireless networking functions.
Technical details
A race condition exists in the Linux kernel's cfg80211 subsystem due to a missing wiphy mutex lock in the cfg80211_check_and_end_cac() function. The vulnerability is triggered when the cfg80211_propagate_cac_done_wk() worker thread calls wdev_chandef() without holding the required mutex, leading to inconsistent state during Channel Availability Check (CAC) propagation. An attacker within radio range (AV:A) could potentially exploit this concurrency issue to cause a kernel panic or achieve broader system compromise. Patches have been released for various stable kernel branches to implement the missing locking mechanism using wiphy_lock() or the guard(wiphy) macro.
Affected products
- Linux Linux Kernel 6.14.0-rc5-wt-g03960e6f9d47 and earlier versions
Timeline
- 2025-07-17: patched: Initial patch submitted by Alexander Wetzel
- 2025-08-22: advisory: CVE-2025-38643 published
References
- https://git.kernel.org/stable/c/2c5dee15239f3f3e31aa5c8808f18996c039e2c1
- https://git.kernel.org/stable/c/4a63523d3541eef4cf504a9682e6fbe94ffe79a6
- https://git.kernel.org/stable/c/7022df2248c08c6f75a01714163ac902333bf3db
- https://git.kernel.org/stable/c/b3d24038eb775f2f7a1dfef58d8e1dc444a12820
- https://git.kernel.org/stable/c/dbce810607726408f889d3358f4780fd1436861e
- https://git.kernel.org/stable/c/defe9ce121160788547e8e6ec4438ad8a14f40dd