Junglewise Threat Intelligence

CVE-2025-39864: Linux Kernel use-after-free in cfg80211 Wi-Fi BSS update

CVE-2025-39864 · Severity: high · CVSS 8.8 · Published 2025-09-19

Technologies: Siemens SCALANCE XR-500, Siemens RUGGEDCOM RST2428P, Siemens SCALANCE XC-300, Siemens SCALANCE XR-500WG, Siemens SCALANCE XR-300, Linux Kernel, Siemens SCALANCE XC-400. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's Wi-Fi management component (cfg80211) that could allow an attacker to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly handles memory for Wi-Fi networks with hidden names (SSIDs). An attacker within Wi-Fi range could exploit this to disrupt network operations or compromise the security of the affected device.

Technical details

A use-after-free (UAF) vulnerability exists in the Linux kernel wifi stack within the `cmp_bss()` and `cfg80211_update_known_bss()` functions in `net/wireless/scan.c`. The root cause is an improper memory management logic where beacon frame elements were being freed even when they were still being shared via the 'hidden_beacon_bss' pointer. This was introduced by a previous refactoring of BSS updates. An attacker within radio range (Adjacent) can trigger this condition by sending specific Wi-Fi management frames, leading to memory corruption. Patches have been released across multiple stable kernel branches to ensure beacon IEs are only freed if they are not shared.

Affected products

  • Linux Linux Kernel Fixed in 26e8444, 5b7ae04, 6854476, 912c4b6, a8bb681, a97a979, b7d0892, ff04056
  • Siemens RUGGEDCOM RST2428P < V3.3
  • Siemens SCALANCE XC-300/XR-300/XC-400/XR-500WG/XR-500 family < V3.3

Timeline

  • 2025-08-13: patched: Initial patch authored
  • 2025-09-19: disclosed: CVE published

References

Related threats