LiveActive security incident?Get immediate response
CVE Record

CVE-2025-38291: wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash Currently, we encounter the following kernel call trace when a firmware crash occurs. This happens because the host sends WMI commands to the firmware while it is in recovery, causing the commands to fail and resulting in the kernel call trace. Set the ATH12K_FLAG_CRASH_FLUSH and ATH12K_FLAG_RECOVERY flags when the host driver receives the firmware crash notification from MHI. This prevents sending WMI commands to the firmware during recovery. Call Trace: <TASK> dump_stack_lvl+0x75/0xc0 register_lock_class+0x6be/0x7a0 ? __lock_acquire+0x644/0x19a0 __lock_acquire+0x95/0x19a0 lock_acquire+0x265/0x310 ? ath12k_ce_send+0xa2/0x210 [ath12k] ? find_held_lock+0x34/0xa0 ? ath12k_ce_send+0x56/0x210 [ath12k] _raw_spin_lock_bh+0x33/0x70 ? ath12k_ce_send+0xa2/0x210 [ath12k] ath12k_ce_send+0xa2/0x210 [ath12k] ath12k_htc_send+0x178/0x390 [ath12k] ath12k_wmi_cmd_send_nowait+0x76/0xa0 [ath12k] ath12k_wmi_cmd_send+0x62/0x190 [ath12k] ath12k_wmi_pdev_bss_chan_info_request+0x62/0xc0 [ath1 ath12k_mac_op_get_survey+0x2be/0x310 [ath12k] ieee80211_dump_survey+0x99/0x240 [mac80211] nl80211_dump_survey+0xe7/0x470 [cfg80211] ? kmalloc_reserve+0x59/0xf0 genl_dumpit+0x24/0x70 netlink_dump+0x177/0x360 __netlink_dump_start+0x206/0x280 genl_family_rcv_msg_dumpit.isra.22+0x8a/0xe0 ? genl_family_rcv_msg_attrs_parse.isra.23+0xe0/0xe0 ? genl_op_lock.part.12+0x10/0x10 ? genl_dumpit+0x70/0x70 genl_rcv_msg+0x1d0/0x290 ? nl80211_del_station+0x330/0x330 [cfg80211] ? genl_get_cmd_both+0x50/0x50 netlink_rcv_skb+0x4f/0x100 genl_rcv+0x1f/0x30 netlink_unicast+0x1b6/0x260 netlink_sendmsg+0x31a/0x450 __sock_sendmsg+0xa8/0xb0 ____sys_sendmsg+0x1e4/0x260 ___sys_sendmsg+0x89/0xe0 ? local_clock_noinstr+0xb/0xc0 ? rcu_is_watching+0xd/0x40 ? kfree+0x1de/0x370 ? __sys_sendmsg+0x7a/0xc0 Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1

HighCVSS 8.8Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A Linux Wi-Fi driver can continue sending commands while compatible Qualcomm ath12k firmware is recovering from a crash, producing a kernel call trace and potentially disrupting the system. Exposure is limited to systems using the affected ath12k path; the supplied evidence does not establish that every Linux system or Wi-Fi device is vulnerable.

Executive priority

Treat as a high-priority reliability and security update for confirmed ath12k deployments, especially business-critical wireless infrastructure. Do not apply the score indiscriminately across all Linux assets. First identify relevant hardware and driver use, then follow supported kernel update channels. Escalate systems showing firmware crashes or kernel traces.

Technical view

When ath12k receives a firmware-crash notification through MHI, recovery flags were not set soon enough. WMI commands could consequently reach unavailable firmware during recovery. The correction sets ATH12K_FLAG_CRASH_FLUSH and ATH12K_FLAG_RECOVERY at notification time, blocking those commands. Testing cited QCN9274 hw2.0 PCI hardware.

Likely exposure

Prioritize Linux hosts using ath12k with compatible Qualcomm wireless hardware, particularly QCN9274 deployments. The supplied affected-version data references Linux 6.13, 6.15.3, and 6.16 but is insufficiently structured to establish a reliable universal version range. Systems without ath12k or relevant hardware are unlikely to reach this code path.

Exploitation context

The source bundle marks this CVE high at CVSS 8.8 with adjacent-network reachability, but provides no demonstrated attack chain. It is not listed in KEV, and no supplied source reports active exploitation. The documented trigger is a firmware crash followed by driver recovery activity.

Researcher notes

The documented defect is a recovery-state race or sequencing failure, not evidence of code execution. The supplied CVSS claims high confidentiality, integrity, and availability impact, while the narrative primarily demonstrates a kernel call trace. Validate impact assumptions against vendor advisories. Exact affected and fixed version boundaries remain unclear from the provided version fields.

Mitigation direction

  • Install a vendor kernel containing the referenced Linux stable correction or an equivalent backport.
  • Prioritize ath12k systems using QCN9274 or other hardware confirmed affected by the Linux vendor.
  • If updating is delayed, consult platform-vendor guidance for supported methods to disable or replace affected wireless hardware.
  • Monitor kernel and wireless-driver logs for firmware crashes, recovery events, and associated call traces.

Validation and detection

  • Inventory systems for the ath12k driver and identify the installed Qualcomm wireless hardware.
  • Record kernel package, build, and distribution backport information; version numbers alone may be insufficient.
  • Confirm vendor changelogs or source history include either referenced stable correction.
  • After updating, verify normal wireless operation and absence of WMI-related call traces during recovery events.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2025-38291 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
0ADP providers
3Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.8CVSS 3.1HighCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H2.85.9Linux

Vulnerability scoring details

Base CVSS 3.1 score

8.8High
CVSS 3.1 vector shape for CVE-2025-38291Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinuxa9b46dd2e483bf99fa09e6aeea7701960abaa902, a9b46dd2e483bf99fa09e6aeea7701960abaa902unaffected
LinuxLinux6.13, 0, 6.15.3, 6.16affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.