
Cloud Vulnerability DB
A community-led vulnerabilities database
A memory leak vulnerability was identified in the Linux kernel's ath12k WiFi driver component, specifically in the ath12kservicereadyextevent function. The vulnerability was assigned CVE-2025-39890 and was disclosed on September 24, 2025. The issue affects the Linux kernel's wireless networking subsystem, particularly the Qualcomm ath12k driver for QCN9274 hardware (NVD).
The vulnerability occurs in the ath12kservicereadyextevent() function where svcrdyext.macphycaps is not properly freed in failure cases. This results in a memory leak of size 1024 bytes. The issue was confirmed through kmemleak traces showing an unreferenced object at address 0xffff8b3eb5789c00. The vulnerability was verified on QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1 hardware (NVD).
The memory leak can lead to gradual system memory depletion over time, potentially affecting system stability and performance. While the leak is relatively small (1024 bytes per occurrence), repeated triggers could accumulate to cause significant memory consumption in long-running systems (NVD).
The fix involves properly freeing svcrdyext.macphycaps in the error case to prevent the memory leak. This has been implemented in the kernel source code and is available through kernel updates (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."