Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-38317

Опубликовано: 10 июл. 2025
Источник: redhat
CVSS3: 6.7
EPSS Низкий

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more than 32 bytes then it results in memory corruption. Fortunately, this is debugfs so it's limited to root users.

Отчет

A buffer overflow was found in the ath12k_write_htt_stats_type() function of the ath12k Wi-Fi driver when writing to a debugfs interface. Specifically, the input buffer was not properly bounded, allowing users to write more than 32 bytes, leading to potential memory corruption. The issue is limited to local, privileged users who have access to debugfs — typically only root or processes with CAP_SYS_ADMIN. Therefore, Privileges Required High (PR:H) for the CVSS. Exploitation does not require user interaction and can lead to limited confidentiality, integrity, and availability impact through memory corruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelAffected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2379183kernel: wifi: ath12k: Fix buffer overflow in debugfs

EPSS

Процентиль: 5%
0.00024
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more than 32 bytes then it results in memory corruption. Fortunately, this is debugfs so it's limited to root users.

nvd
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more than 32 bytes then it results in memory corruption. Fortunately, this is debugfs so it's limited to root users.

debian
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: w ...

github
около 1 месяца назад

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix buffer overflow in debugfs If the user tries to write more than 32 bytes then it results in memory corruption. Fortunately, this is debugfs so it's limited to root users.

CVSS3: 6.7
fstec
4 месяца назад

Уязвимость компонента wifi ядра операционной системы Linux, позволяющая нарушителю повредить память

EPSS

Процентиль: 5%
0.00024
Низкий

6.7 Medium

CVSS3