CVE-2025-38291: wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: Prevent sending WMI commands to firmware during firmware crash
Currently, we encounter the following kernel call trace when a firmware
crash occurs. This happens because the host sends WMI commands to the
firmware while it is in recovery, causing the commands to fail and
resulting in the kernel call trace.
Set the ATH12K_FLAG_CRASH_FLUSH and ATH12K_FLAG_RECOVERY flags when the
host driver receives the firmware crash notification from MHI. This
prevents sending WMI commands to the firmware during recovery.
Call Trace:
<TASK>
dump_stack_lvl+0x75/0xc0
register_lock_class+0x6be/0x7a0
? __lock_acquire+0x644/0x19a0
__lock_acquire+0x95/0x19a0
lock_acquire+0x265/0x310
? ath12k_ce_send+0xa2/0x210 [ath12k]
? find_held_lock+0x34/0xa0
? ath12k_ce_send+0x56/0x210 [ath12k]
_raw_spin_lock_bh+0x33/0x70
? ath12k_ce_send+0xa2/0x210 [ath12k]
ath12k_ce_send+0xa2/0x210 [ath12k]
ath12k_htc_send+0x178/0x390 [ath12k]
ath12k_wmi_cmd_send_nowait+0x76/0xa0 [ath12k]
ath12k_wmi_cmd_send+0x62/0x190 [ath12k]
ath12k_wmi_pdev_bss_chan_info_request+0x62/0xc0 [ath1
ath12k_mac_op_get_survey+0x2be/0x310 [ath12k]
ieee80211_dump_survey+0x99/0x240 [mac80211]
nl80211_dump_survey+0xe7/0x470 [cfg80211]
? kmalloc_reserve+0x59/0xf0
genl_dumpit+0x24/0x70
netlink_dump+0x177/0x360
__netlink_dump_start+0x206/0x280
genl_family_rcv_msg_dumpit.isra.22+0x8a/0xe0
? genl_family_rcv_msg_attrs_parse.isra.23+0xe0/0xe0
? genl_op_lock.part.12+0x10/0x10
? genl_dumpit+0x70/0x70
genl_rcv_msg+0x1d0/0x290
? nl80211_del_station+0x330/0x330 [cfg80211]
? genl_get_cmd_both+0x50/0x50
netlink_rcv_skb+0x4f/0x100
genl_rcv+0x1f/0x30
netlink_unicast+0x1b6/0x260
netlink_sendmsg+0x31a/0x450
__sock_sendmsg+0xa8/0xb0
____sys_sendmsg+0x1e4/0x260
___sys_sendmsg+0x89/0xe0
? local_clock_noinstr+0xb/0xc0
? rcu_is_watching+0xd/0x40
? kfree+0x1de/0x370
? __sys_sendmsg+0x7a/0xc0
Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1
Security readout for executives and security teams
Plain-English summary
A Linux Wi-Fi driver can continue sending commands while compatible Qualcomm ath12k firmware is recovering from a crash, producing a kernel call trace and potentially disrupting the system. Exposure is limited to systems using the affected ath12k path; the supplied evidence does not establish that every Linux system or Wi-Fi device is vulnerable.
Executive priority
Treat as a high-priority reliability and security update for confirmed ath12k deployments, especially business-critical wireless infrastructure. Do not apply the score indiscriminately across all Linux assets. First identify relevant hardware and driver use, then follow supported kernel update channels. Escalate systems showing firmware crashes or kernel traces.
Technical view
When ath12k receives a firmware-crash notification through MHI, recovery flags were not set soon enough. WMI commands could consequently reach unavailable firmware during recovery. The correction sets ATH12K_FLAG_CRASH_FLUSH and ATH12K_FLAG_RECOVERY at notification time, blocking those commands. Testing cited QCN9274 hw2.0 PCI hardware.
Likely exposure
Prioritize Linux hosts using ath12k with compatible Qualcomm wireless hardware, particularly QCN9274 deployments. The supplied affected-version data references Linux 6.13, 6.15.3, and 6.16 but is insufficiently structured to establish a reliable universal version range. Systems without ath12k or relevant hardware are unlikely to reach this code path.
Exploitation context
The source bundle marks this CVE high at CVSS 8.8 with adjacent-network reachability, but provides no demonstrated attack chain. It is not listed in KEV, and no supplied source reports active exploitation. The documented trigger is a firmware crash followed by driver recovery activity.
Researcher notes
The documented defect is a recovery-state race or sequencing failure, not evidence of code execution. The supplied CVSS claims high confidentiality, integrity, and availability impact, while the narrative primarily demonstrates a kernel call trace. Validate impact assumptions against vendor advisories. Exact affected and fixed version boundaries remain unclear from the provided version fields.
Mitigation direction
Install a vendor kernel containing the referenced Linux stable correction or an equivalent backport.
Prioritize ath12k systems using QCN9274 or other hardware confirmed affected by the Linux vendor.
If updating is delayed, consult platform-vendor guidance for supported methods to disable or replace affected wireless hardware.
Monitor kernel and wireless-driver logs for firmware crashes, recovery events, and associated call traces.
Validation and detection
Inventory systems for the ath12k driver and identify the installed Qualcomm wireless hardware.
Record kernel package, build, and distribution backport information; version numbers alone may be insufficient.
Confirm vendor changelogs or source history include either referenced stable correction.
After updating, verify normal wireless operation and absence of WMI-related call traces during recovery events.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38291 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
3Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.