In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: regulatory: improve invalid hints checking
Syzbot keeps reporting an issue [1] that occurs when erroneous symbols
sent from userspace get through into user_alpha2[] via
regulatory_hint_user() call. Such invalid regulatory hints should be
rejected.
While a sanity check from commit 47caf685a685 ("cfg80211: regulatory:
reject invalid hints") looks to be enough to deter these very cases,
there is a way to get around it due to 2 reasons.
1) The way isalpha() works, symbols other than latin lower and
upper letters may be used to determine a country/domain.
For instance, greek letters will also be considered upper/lower
letters and for such characters isalpha() will return true as well.
However, ISO-3166-1 alpha2 codes should only hold latin
characters.
2) While processing a user regulatory request, between
reg_process_hint_user() and regulatory_hint_user() there happens to
be a call to queue_regulatory_request() which modifies letters in
request->alpha2[] with toupper(). This works fine for latin symbols,
less so for weird letter characters from the second part of _ctype[].
Syzbot triggers a warning in is_user_regdom_saved() by first sending
over an unexpected non-latin letter that gets malformed by toupper()
into a character that ends up failing isalpha() check.
Prevent this by enhancing is_an_alpha2() to ensure that incoming
symbols are latin letters and nothing else.
[1] Syzbot report:
------------[ cut here ]------------
Unexpected user alpha2: A�
WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 is_user_regdom_saved net/wireless/reg.c:440 [inline]
WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_alpha2 net/wireless/reg.c:3424 [inline]
WARNING: CPU: 1 PID: 964 at net/wireless/reg.c:442 restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516
Modules linked in:
CPU: 1 UID: 0 PID: 964 Comm: kworker/1:2 Not tainted 6.12.0-rc5-syzkaller-00044-gc1e939a21eb1 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Workqueue: events_power_efficient crda_timeout_work
RIP: 0010:is_user_regdom_saved net/wireless/reg.c:440 [inline]
RIP: 0010:restore_alpha2 net/wireless/reg.c:3424 [inline]
RIP: 0010:restore_regulatory_settings+0x3c0/0x1e50 net/wireless/reg.c:3516
...
Call Trace:
<TASK>
crda_timeout_work+0x27/0x50 net/wireless/reg.c:542
process_one_work kernel/workqueue.c:3229 [inline]
process_scheduled_works+0xa65/0x1850 kernel/workqueue.c:3310
worker_thread+0x870/0xd30 kernel/workqueue.c:3391
kthread+0x2f2/0x390 kernel/kthread.c:389
ret_from_fork+0x4d/0x80 arch/x86/kernel/process.c:147
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244
</TASK>
Security readout for executives and security teams
Plain-English summary
This Linux kernel issue lets invalid non-Latin country-code input reach Wi-Fi regulatory handling and trigger a kernel warning. The source describes a robustness flaw found by syzbot, not confirmed real-world compromise. Business urgency depends on where affected Linux kernels with wireless regulatory support are deployed.
Executive priority
Treat as a routine-to-moderate kernel maintenance item unless affected systems are stability-sensitive or broadly allow untrusted local users. There is no source-backed active exploitation signal, but kernel warning paths should still be patched through normal vendor update processes.
Technical view
cfg80211 regulatory code accepted characters that isalpha() treated as letters, including non-Latin input. During user regulatory hint processing, toupper() could transform that input into malformed alpha2 data, later triggering an unexpected user alpha2 warning. The fix restricts alpha2 validation to Latin letters only.
Likely exposure
Affected Linux kernels using the cfg80211 Wi-Fi regulatory subsystem may be exposed. The source indicates input arrives from userspace through regulatory_hint_user(), so exposure appears local or userspace-adjacent rather than remote network-based. Exact distro package impact requires vendor mapping.
Exploitation context
The bundle reports syzbot triggering a kernel warning with malformed regulatory symbols. KEV is false, and no cited source states active exploitation or a public weaponized exploit. Impact beyond warning or stability risk is not quantified in the provided evidence.
Researcher notes
Focus analysis on cfg80211 regulatory hint validation, especially is_an_alpha2(), isalpha(), and toupper() behavior for non-Latin characters. The provided evidence supports malformed userspace input causing a warning; it does not establish privilege escalation, remote attack, or broader memory corruption.
Mitigation direction
Apply vendor kernel updates that include the stable fixes for CVE-2025-21910.
For Debian LTS systems, follow the referenced Debian security advisories.
Prioritize Linux systems using Wi-Fi or cfg80211 regulatory functionality.
If vendor status is unclear, track the listed Linux stable commits.
Avoid inventing workarounds; use vendor kernel guidance.
Validation and detection
Inventory Linux kernel versions and map them to vendor-fixed packages.
Check whether systems load or rely on cfg80211 wireless regulatory code.
Review kernel logs for unexpected user alpha2 warnings.
Confirm package changelogs reference CVE-2025-21910 or listed stable commits.
Validate Debian LTS hosts against the cited Debian advisories.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21910 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
1ADP providers
11Source links
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Apr 1, 2025, 15:40 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.