Bug 2419888 (CVE-2025-40321)
| Summary: | CVE-2025-40321 kernel: wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel’s Broadcom FullMAC Wi-Fi driver where, under standalone AP mode (hostapd managing the interface without a P2P virtual interface), the driver always attempts to use a P2P interface pointer that may not be initialized when transmitting certain Action frames. If an ANQP Query Request Action frame is received from an unassociated station, this uninitialized pointer is dereferenced, leading to a NULL pointer dereference and kernel crash.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2025-12-08 07:06:24 UTC
|