CVE-2025-39862: wifi: mt76: mt7915: fix list corruption after hardware restart
In the Linux kernel, the following vulnerability has been resolved:
wifi: mt76: mt7915: fix list corruption after hardware restart
Since stations are recreated from scratch, all lists that wcids are added to must be cleared before calling ieee80211restarthw. Set wcid->sta = 0 for each wcid entry in order to ensure that they are not added again before they are ready.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
For each wcid entry, set wcid->sta = 0 so wcid lists are cleared before calling ieee80211_restart_hw, preventing list corruption after hardware restart.
Linux kernel (wifi: mt76: mt7915) wcid->sta = 0
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39862?
CVE-2025-39862 is classified as a moderate severity vulnerability in the Linux kernel.
How do I fix CVE-2025-39862?
To resolve CVE-2025-39862, users should update their Linux kernel to the latest patched version provided by their distribution.
What type of attack does CVE-2025-39862 enable?
CVE-2025-39862 could potentially allow an attacker to exploit list corruption issues during a hardware restart.
Which versions of the Linux kernel are affected by CVE-2025-39862?
CVE-2025-39862 affects specific versions of the Linux kernel that utilize the mt76 driver, particularly for the mt7915 chipset.
Is CVE-2025-39862 related to wireless networking issues?
Yes, CVE-2025-39862 specifically pertains to vulnerabilities in the wireless networking stack of the Linux kernel.