CVE-2025-39849

HIGH EPSS 4.1%
Published Sep 19, 20259mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Sep 19, 2025 9mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() If the ssid->datalen is more than IEEE80211_MAX_SSID_LEN (32) it would lead to memory corruption so add some bounds checking.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
4.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-787 Out-of-bounds Write Memory Safety

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥6.1.16  –  <6.1.151
linuxlinux_kernel*≥6.2.3  –  <6.6.105
linuxlinux_kernel*≥6.7  –  <6.12.46
linuxlinux_kernel*≥6.13  –  <6.16.6
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
linuxlinux_kernel6.17any
debiandebian_linux11.0any

References 7

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-032379.html
  • git.kernel.org https://git.kernel.org/stable/c/31229145e6ba5ace3e9391113376fa05b7831ede
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5cb7cab7adf9b1e6a99e2081b0e30e9e59d07523
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/62b635dcd69c4fde7ce1de4992d71420a37e51e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8e751d46336205abc259ed3990e850a9843fb649
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e472f59d02c82b511bc43a3f96d62ed08bf4537f
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/31229145e6ba5ace3e9391113376fa05b7831ede
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5cb7cab7adf9b1e6a99e2081b0e30e9e59d07523
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/62b635dcd69c4fde7ce1de4992d71420a37e51e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8e751d46336205abc259ed3990e850a9843fb649
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e472f59d02c82b511bc43a3f96d62ed08bf4537f
    Patch