CVE-2025-38601: wifi: ath11k: clear initialized flag for deinit-ed srng lists
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath11k: clear initialized flag for deinit-ed srng lists
In a number of cases we see kernel panics on resume due
to ath11k kernel page fault, which happens under the
following circumstances:
1) First ath11k_hal_dump_srng_stats() call
Last interrupt received for each group:
ath11k_pci 0000:01:00.0: group_id 0 22511ms before
ath11k_pci 0000:01:00.0: group_id 1 14440788ms before
[..]
ath11k_pci 0000:01:00.0: failed to receive control response completion, polling..
ath11k_pci 0000:01:00.0: Service connect timeout
ath11k_pci 0000:01:00.0: failed to connect to HTT: -110
ath11k_pci 0000:01:00.0: failed to start core: -110
ath11k_pci 0000:01:00.0: firmware crashed: MHI_CB_EE_RDDM
ath11k_pci 0000:01:00.0: already resetting count 2
ath11k_pci 0000:01:00.0: failed to wait wlan mode request (mode 4): -110
ath11k_pci 0000:01:00.0: qmi failed to send wlan mode off: -110
ath11k_pci 0000:01:00.0: failed to reconfigure driver on crash recovery
[..]
2) At this point reconfiguration fails (we have 2 resets) and
ath11k_core_reconfigure_on_crash() calls ath11k_hal_srng_deinit()
which destroys srng lists. However, it does not reset per-list
->initialized flag.
3) Second ath11k_hal_dump_srng_stats() call sees stale ->initialized
flag and attempts to dump srng stats:
Last interrupt received for each group:
ath11k_pci 0000:01:00.0: group_id 0 66785ms before
ath11k_pci 0000:01:00.0: group_id 1 14485062ms before
ath11k_pci 0000:01:00.0: group_id 2 14485062ms before
ath11k_pci 0000:01:00.0: group_id 3 14485062ms before
ath11k_pci 0000:01:00.0: group_id 4 14780845ms before
ath11k_pci 0000:01:00.0: group_id 5 14780845ms before
ath11k_pci 0000:01:00.0: group_id 6 14485062ms before
ath11k_pci 0000:01:00.0: group_id 7 66814ms before
ath11k_pci 0000:01:00.0: group_id 8 68997ms before
ath11k_pci 0000:01:00.0: group_id 9 67588ms before
ath11k_pci 0000:01:00.0: group_id 10 69511ms before
BUG: unable to handle page fault for address: ffffa007404eb010
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 100000067 P4D 100000067 PUD 10022d067 PMD 100b01067 PTE 0
Oops: 0000 [#1] PREEMPT SMP NOPTI
RIP: 0010:ath11k_hal_dump_srng_stats+0x2b4/0x3b0 [ath11k]
Call Trace:
<TASK>
? __die_body+0xae/0xb0
? page_fault_oops+0x381/0x3e0
? exc_page_fault+0x69/0xa0
? asm_exc_page_fault+0x22/0x30
? ath11k_hal_dump_srng_stats+0x2b4/0x3b0 [ath11k (HASH:6cea 4)]
ath11k_qmi_driver_event_work+0xbd/0x1050 [ath11k (HASH:6cea 4)]
worker_thread+0x389/0x930
kthread+0x149/0x170
Clear per-list ->initialized flag in ath11k_hal_srng_deinit().
Security readout for executives and security teams
Plain-English summary
A Linux Wi-Fi driver flaw can crash the operating system during resume or recovery from Qualcomm ath11k firmware failures. The driver may treat destroyed ring data as initialized and read invalid kernel memory. Affected laptops, access points, or appliances could lose availability and require recovery or reboot.
Executive priority
Treat as a high-priority stability and availability issue for ath11k-equipped systems, especially operational appliances and frequently suspended endpoints. Patch through supported kernel channels after normal compatibility testing. Broader emergency action is not supported by the current exploitation evidence.
Technical view
ath11k_hal_srng_deinit() destroys SRNG lists without clearing each list's initialized flag. After failed ath11k crash reconfiguration, a later statistics dump trusts the stale flag and accesses deinitialized memory, causing a supervisor-mode page fault and kernel panic. The published fix clears the flag during deinitialization.
Likely exposure
Exposure is limited to Linux systems using the ath11k Wi-Fi driver and vulnerable kernel builds, particularly systems exercising suspend, resume, or firmware-crash recovery. The bundle lists several affected versions, but its version encoding is ambiguous; confirm fixed or backported status with the operating-system vendor.
Exploitation context
The supplied record marks this CVE as absent from KEV, and no cited source establishes active exploitation or a public exploit. Documented failures involve firmware crashes, repeated reset failures, resume, and subsequent statistics collection. The adjacent-network CVSS vector indicates potential remote proximity, but the sources do not demonstrate a reliable attacker-controlled trigger.
Researcher notes
The supplied CVSS is 8.8 with adjacent attack vector and high confidentiality, integrity, and availability impacts. However, the narrative directly demonstrates a stale-state memory access and kernel panic, not proven data disclosure, modification, or attacker control. Reproduction and exploitability evidence are incomplete, so impact claims should remain conservative.
Mitigation direction
Install a vendor-supported kernel containing the linked ath11k fix or an equivalent backport.
Check distribution security guidance to identify the corrected package for each deployed kernel branch.
Prioritize systems using ath11k that suspend frequently or have recorded Wi-Fi firmware recovery failures.
Use vendor-recommended operational workarounds if immediate kernel replacement is unavailable.
Validation and detection
Inventory Linux systems using the ath11k driver and record their exact kernel package versions.
Confirm the installed kernel includes the stable fix or a distribution-maintained equivalent backport.
Review kernel logs for ath11k recovery failures, page faults, or ath11k_hal_dump_srng_stats panics.
After remediation, validate suspend, resume, and normal Wi-Fi recovery under controlled conditions.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38601 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
11Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.