Security readout for executives and security teams
Plain-English summary
A Linux Wi-Fi driver flaw can corrupt kernel memory bookkeeping when a device resumes from sleep and Wake-on-WLAN recovery fails. The documented result is a kernel BUG and system crash. It affects systems using the rtw89 driver in the identified kernel revisions, not every Linux system.
Executive priority
Treat this as a high-priority reliability and endpoint-security update for affected rtw89 fleets, especially laptops using sleep and Wake-on-WLAN. It is not documented as internet-reachable or actively exploited, so scope remediation by hardware, driver, and kernel version rather than launching an organization-wide emergency response.
Technical view
During failed WoWLAN resume, rtw89 can add an interface again without first removing it. This reinitializes the management-entry list and permits the same node to be inserted twice, producing list corruption and a kernel BUG. The referenced fixes add a check preventing duplicate insertion.
Likely exposure
Exposure requires an affected Linux kernel, rtw89-compatible Wi-Fi hardware, and the failed WoWLAN resume path. The bundle identifies affected 6.13 and 6.14-related revisions, but its flattened version data does not establish precise downstream distribution versions. Confirm vendor backport status directly.
Exploitation context
The supplied CVSS vector describes local, low-privileged attack proximity with no user interaction. CISA KEV status is false, and the sources provide no evidence of active exploitation or a public exploit. They demonstrate a crash but do not establish reliable attacker control or remote exploitation.
Researcher notes
No CWE is supplied. The evidence shows an erroneous double list insertion following failed WoWLAN resume and a resulting kernel BUG. It does not independently demonstrate arbitrary code execution, confidentiality loss, integrity loss, or attacker-controlled triggering. Three Linux stable-tree fix references are provided.
Mitigation direction
Install a vendor-supported kernel containing the applicable referenced stable fix or backport.
Check distribution or device-vendor guidance for exact fixed package versions.
Prioritize systems using rtw89 Wi-Fi hardware and Wake-on-WLAN.
If updates are unavailable, request vendor guidance; the sources identify no tested workaround.
Validation and detection
Inventory kernel versions and systems loading an rtw89 driver.
Confirm the installed kernel includes an applicable fix commit or documented vendor backport.
Review kernel logs for WoWLAN resume failures, list_add corruption, or kernel BUG messages.
Validate ordinary suspend and resume behavior after updating in a controlled environment.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21730 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
4Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.