
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39864 is a recently discovered vulnerability in the Linux kernel affecting the wifi subsystem, specifically in the cfg80211 component. The vulnerability was disclosed on September 19, 2025, and involves a use-after-free issue in the cmp_bss() function (NVD).
The vulnerability stems from a use-after-free condition in the cmpbss() function within the cfg80211 component of the Linux kernel's wifi subsystem. The issue was introduced following a bssfree() quirk in commit 776b3580178f which was intended to track hidden SSID networks properly. The vulnerability specifically relates to the handling of beacon frame elements in the cfg80211updateknown_bss() function (NVD).
The vulnerability could potentially lead to memory corruption in the Linux kernel's wifi subsystem, which might result in system crashes or potential privilege escalation. The issue affects the handling of beacon frame elements in wireless network operations (NVD).
The fix involves adjusting the cfg80211updateknownbss() function to ensure beacon frame elements are only freed if they're not shared via the corresponding 'hiddenbeacon_bss' pointer. Users are advised to update their Linux kernel to a patched version when available (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."