LiveActive security incident?Get immediate response
CVE Record

CVE-2025-21910: wifi: cfg80211: regulatory: improve invalid hints checking

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: regulatory: improve invalid hints checking Syzbot keeps reporting an issue [1] that occurs when erroneous symbols sent from userspace get through into user_alpha2[] via regulatory_hint_user() call. Such invalid regulatory hints should be rejected. While a sanity check from commit 47caf685a685 ("cfg80211: regulatory: reject invalid hints") looks to be enough to deter these very cases, there is a way to get around it due to 2 reasons. 1) The way isalpha() works, symbols other than latin lower and upper letters may be used to determine a country/domain. For instance, greek letters will also be considered upper/lower letters and for such characters isalpha() will return true as well. However, ISO-3166-1 alpha2 codes should only hold latin characters. 2) While processing a user regulatory request, between reg_process_hint_user() and regulatory_hint_user() there happens to be a call to queue_regulatory_request() which modifies letters in request->alpha2[] with toupper(). This works fine for latin symbols, less so for weird letter characters from the second part of _ctype[]. Syzbot triggers a warning in is_user_regdom_saved() by first sending over an unexpected non-latin letter that gets malformed by toupper() into a character that ends up failing isalpha() check. Prevent this by enhancing is_an_alpha2() to ensure that incoming symbols are latin letters and nothing else. [1] Syzbot report: ------------[ cut here ]------------ Unexpected user alpha2: A� WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 is_user_regdom_saved net/wireless/reg.c:440 [inline] WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_alpha2 net/wireless/reg.c:3424 [inline] WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516 Modules linked in: CPU: 1 UID: 0 PID: 964 Comm: kworker/1:2 Not tainted 6.12.0-rc5-syzkaller-00044-gc1e939a21eb1 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: events_power_efficient crda_timeout_work RIP: 0010:is_user_regdom_saved net/wireless/reg.c:440 [inline] RIP: 0010:restore_alpha2 net/wireless/reg.c:3424 [inline] RIP: 0010:restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516 ... Call Trace: <TASK> crda_timeout_work+0x27/0x50 net/wireless/reg.c:542 process_one_work kernel/workqueue.c:3229 [inline] process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310 worker_thread+0x870/0xd30 kernel/workqueue.c:3391 kthread+0x2f2/0x390 kernel/kthread.c:389 ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244 </TASK>

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

This Linux kernel issue lets invalid non-Latin country-code input reach Wi-Fi regulatory handling and trigger a kernel warning. The source describes a robustness flaw found by syzbot, not confirmed real-world compromise. Business urgency depends on where affected Linux kernels with wireless regulatory support are deployed.

Executive priority

Treat as a routine-to-moderate kernel maintenance item unless affected systems are stability-sensitive or broadly allow untrusted local users. There is no source-backed active exploitation signal, but kernel warning paths should still be patched through normal vendor update processes.

Technical view

cfg80211 regulatory code accepted characters that isalpha() treated as letters, including non-Latin input. During user regulatory hint processing, toupper() could transform that input into malformed alpha2 data, later triggering an unexpected user alpha2 warning. The fix restricts alpha2 validation to Latin letters only.

Likely exposure

Affected Linux kernels using the cfg80211 Wi-Fi regulatory subsystem may be exposed. The source indicates input arrives from userspace through regulatory_hint_user(), so exposure appears local or userspace-adjacent rather than remote network-based. Exact distro package impact requires vendor mapping.

Exploitation context

The bundle reports syzbot triggering a kernel warning with malformed regulatory symbols. KEV is false, and no cited source states active exploitation or a public weaponized exploit. Impact beyond warning or stability risk is not quantified in the provided evidence.

Researcher notes

Focus analysis on cfg80211 regulatory hint validation, especially is_an_alpha2(), isalpha(), and toupper() behavior for non-Latin characters. The provided evidence supports malformed userspace input causing a warning; it does not establish privilege escalation, remote attack, or broader memory corruption.

Mitigation direction

  • Apply vendor kernel updates that include the stable fixes for CVE-2025-21910.
  • For Debian LTS systems, follow the referenced Debian security advisories.
  • Prioritize Linux systems using Wi-Fi or cfg80211 regulatory functionality.
  • If vendor status is unclear, track the listed Linux stable commits.
  • Avoid inventing workarounds; use vendor kernel guidance.

Validation and detection

  • Inventory Linux kernel versions and map them to vendor-fixed packages.
  • Check whether systems load or rely on cfg80211 wireless regulatory code.
  • Review kernel logs for unexpected user alpha2 warnings.
  • Confirm package changelogs reference CVE-2025-21910 or listed stable commits.
  • Validate Debian LTS hosts against the cited Debian advisories.
Prepared
Confidence
medium
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-21910 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
1ADP providers
11Source links

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7e, 09d989d179d0c679043556dda77c51b41a2dae7eunaffected
LinuxLinux2.6.34, 0, 5.4.291, 5.10.235, 5.15.179, 6.1.131, 6.6.83, 6.12.19, 6.13.7, 6.14affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.