Junglewise Threat Intelligence

CVE-2025-39732: Linux Kernel ath11k Wi-Fi driver sleeping-in-atomic in bitrate mask handling

CVE-2025-39732 · Severity: high · CVSS 7.8 · Published 2025-09-07

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Qualcomm ath11k Wi-Fi driver. The issue occurs when the system attempts to set Wi-Fi bitrate masks, potentially causing the system to crash or become unstable due to an invalid execution context. This could allow a local user with basic privileges to disrupt system operations or potentially gain unauthorized access to system resources.

Technical details

The vulnerability is a 'sleeping-in-atomic' bug within the ath11k Wi-Fi driver, specifically in the ath11k_mac_op_set_bitrate_mask() function. The root cause is the use of ath11k_mac_disable_peer_fixed_rate() as an iterator for ieee80211_iterate_stations_atomic(). Because the iterator function may sleep (via ath11k_wmi_cmd_send), it violates the requirements of the atomic iteration context, leading to a kernel panic or 'BUG: sleeping function called from invalid context'. An attacker with local access could trigger this condition to cause a Denial of Service (DoS) or potentially exploit the resulting unstable state for further privilege escalation. The fix involves switching to the mutex-protected iterator ieee80211_iterate_stations_mtx().

Affected products

  • Linux Linux Kernel 5.6 to 6.12.41, 6.13 to 6.15.9, 6.16 to 6.16.0

Timeline

  • 2025-09-07: disclosed
  • 2025-09-07: advisory
  • 2025-08-15: patched: Patched in stable branches 6.12.42, 6.15.10, 6.16.1

References

Related threats