Junglewise Threat Intelligence

CVE-2025-39750: Linux Kernel ath12k out-of-bounds access in TID cleanup

CVE-2025-39750 · Severity: high · CVSS 8.8 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Qualcomm Wi-Fi driver (ath12k) could allow an attacker to cause a system crash or access restricted memory. The issue occurs when the system fails to set up certain wireless data structures and incorrectly attempts to clean up resources that were never properly assigned. This can lead to operational instability or potential data exposure on devices using affected Qualcomm Wi-Fi chips.

Technical details

An issue exists in the ath12k wireless driver within the Linux kernel's data path (dp.c) component. Specifically, in the ath12k_dp_rx_peer_tid_setup() function, a Traffic Identifier (TID) counter is incremented before successful allocation. If a subsequent error occurs, the cleanup routine ath12k_dp_rx_peer_tid_delete() is called with an unallocated TID index. This logic error results in an attempt to free unallocated resources, potentially causing a kernel crash (DoS) or out-of-bounds memory access. The vulnerability is reachable via local or adjacent network vectors depending on the specific wireless environment and peer interactions. Patches have been released across multiple stable kernel branches to ensure the TID counter is correctly decremented before cleanup.

Affected products

  • Linux Linux Kernel 6.3 to 6.6.102, 6.7 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-07-21: patched: Initial fix committed to kernel source
  • 2025-09-11: disclosed: CVE published

References

Related threats