Junglewise Threat Intelligence

CVE-2025-39952: Linux Kernel wilc1000 buffer overflow in WID string configuration

CVE-2025-39952 · Severity: high · CVSS 8.8 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel driver for Microchip WILC1000 wireless network cards. The flaw exists in how the driver processes configuration data received from the device's firmware, which could allow a malicious or compromised firmware to overwrite system memory. This could lead to a complete system crash or allow an attacker to gain unauthorized control over the operating system.

Technical details

A heap-based buffer overflow (CWE-787) exists in the wilc1000 wireless driver within the `wilc_wlan_parse_response_frame()` function in `drivers/net/wireless/microchip/wilc1000/wlan_cfg.c`. The vulnerability is caused by a lack of size validation when performing a `memcpy` of WID (Wireless Identifier) string configuration data from a firmware response frame into the `cfg->s[i]->str` buffer. An attacker with the ability to provide malicious firmware responses (e.g., via a compromised wireless chipset) can trigger a copy overflow (e.g., 65537 bytes into a 512-byte buffer). The fix introduces explicit size checks based on the WID type and the destination buffer's defined length. Patches are available in stable kernel branches 6.6.108, 6.12.49, and 6.16.9.

Affected products

  • Linux Linux Kernel 4.2 to 6.6.108, 6.7 to 6.12.49, 6.13 to 6.16.9

Timeline

  • 2025-08-29: patched: Initial patch authored by Microchip
  • 2025-10-04: disclosed: CVE published

References

Related threats