Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at this point etc., so the WARN_ON() doesn't add any value. Additionally, this is one of the top syzbot reports now. Just print a message, and as an added bonus, print the sizes too.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 5.4.296 |
| Debian | Debian Linux | 11.0 |
References
- https://git.kernel.org/stable/c/27d07deea35ae67f2e75913242e25bdb7e1114e5Patch
- https://git.kernel.org/stable/c/327997afbb5e62532c28c1861ab5534c01969c9aPatch
- https://git.kernel.org/stable/c/347827bd0c5680dac2dd59674616840c4d5154f1Patch
- https://git.kernel.org/stable/c/46b47d4b06fa7f234d93f0f8ac43798feafcff89Patch
- https://git.kernel.org/stable/c/7a2afdc5af3b82b601f6a2f0d1c90d5f0bc27aebPatch
- https://git.kernel.org/stable/c/89bd133529a4d2d68287128b357e49adc00ec690Patch
- https://git.kernel.org/stable/c/e6c49f0b203a987c306676d241066451b74db1a5Patch
- https://git.kernel.org/stable/c/e7417421d89358da071fd2930f91e67c7128fbffPatch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
FAQ
What is CVE-2025-38406?
CVE-2025-38406 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: remove WARN on bad firmware input If the firmware gives bad input, that's nothing to do with the driver's stack at t...
How severe is CVE-2025-38406?
CVE-2025-38406 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38406?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.