NULL pointer dereference in Linux kernel - CVE-2025-38606
Published: August 20, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ath12k_p2p_noa_update_vdev_iter() function in drivers/net/wireless/ath/ath12k/p2p.c, within the ath12k_get_arvif_iter(), ath12k_mac_handle_beacon_iter(), ath12k_mac_handle_beacon_miss_iter(), ath12k_mac_change_chanctx_cnt_iter() and ath12k_mac_change_chanctx_fill_iter() functions in drivers/net/wireless/ath/ath12k/mac.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-oem-6.14 (Ubuntu package)
linux-realtime-6.14 (Ubuntu package)
linux-azure (Ubuntu package)
linux-aws-6.14 (Ubuntu package)
linux-gcp-6.14 (Ubuntu package)
How to mitigate CVE-2025-38606
linux-oem-6.14 (Ubuntu package) - update to 6.14.0-1016.16
linux-realtime-6.14 (Ubuntu package) - update to 6.14.0-1016.16~24.04.1
linux-azure (Ubuntu package) - addressed in versions 6.14.0-1017.17, 6.14.0-1017.17~24.04.1
linux-aws-6.14 (Ubuntu package) - update to 6.14.0-1017.17~24.04.1
linux-gcp-6.14 (Ubuntu package) - addressed in versions 6.14.0-1018.18, 6.14.0-1020.21~24.04.1