CVE-2025-38291
Linux Kernel vulnerability analysis and mitigation

Overview

A vulnerability in the Linux kernel's ath12k WiFi driver was discovered and assigned CVE-2025-38291. The issue was disclosed on July 10, 2025, affecting the kernel's handling of WMI commands during firmware crash recovery. The vulnerability specifically impacts the QCN9274 hw2.0 PCI WLAN hardware running WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1 firmware (NVD).

Technical details

The vulnerability occurs when the host sends WMI commands to the firmware while it is in recovery mode after a crash. This results in command failures and generates kernel call traces. The technical issue stems from improper handling of the firmware recovery state, where the host continues to send commands despite the firmware being in an unstable state (NVD).

Impact

When exploited, this vulnerability causes kernel call traces and potential system instability. The issue affects the WiFi functionality of systems using the ath12k driver, particularly during firmware crash recovery scenarios (NVD).

Mitigation and workarounds

The fix involves setting the ATH12KFLAGCRASHFLUSH and ATH12KFLAG_RECOVERY flags when the host driver receives the firmware crash notification from MHI. This prevents the sending of WMI commands to the firmware during the recovery process (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-rt-64k
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-modules-extra
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-devel-matched
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-64k-debug-modules-partner
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management