CVE-2025-39864

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/09/2025
Last modified:
19/09/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> wifi: cfg80211: fix use-after-free in cmp_bss()<br /> <br /> Following bss_free() quirk introduced in commit 776b3580178f<br /> ("cfg80211: track hidden SSID networks properly"), adjust<br /> cfg80211_update_known_bss() to free the last beacon frame<br /> elements only if they&amp;#39;re not shared via the corresponding<br /> &amp;#39;hidden_beacon_bss&amp;#39; pointer.

Impact