SB2025040286 - Improper locking in Linux kernel wireless
Published: April 2, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-21910)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the is_an_alpha2() function in net/wireless/reg.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/17aa34c84867f6cd181a5743e1c647e7766962a6
- https://git.kernel.org/stable/c/35ef07112b61b06eb30683a6563c9f6378c02476
- https://git.kernel.org/stable/c/59b348be7597c4a9903cb003c69e37df20c04a30
- https://git.kernel.org/stable/c/62b1a9bbfebba4b4c2bb6c1ede9ef7ecee7a9ff6
- https://git.kernel.org/stable/c/6a5e3b23054cee3b92683d1467e3fa83921f5622
- https://git.kernel.org/stable/c/be7c5f00aa7f1344293e4d48d0e12be83a2f223d
- https://git.kernel.org/stable/c/da3f599517ef2ea851208df3229d07728d238dc5
- https://git.kernel.org/stable/c/f4112cb477c727a65787a4065a75ca593bb5b2f4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.131