In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix memory leak in ath12kpciremove()
Kmemleak reported this error:
unreferenced object 0xffff1c165cec3060 (size 32): comm "insmod", pid 560, jiffies 4296964570 (age 235.596s) backtrace: [<000000005434db68>] _kmemcacheallocnode+0x1f4/0x2c0 [<000000001203b155>] kmalloctrace+0x40/0x88 [<0000000028adc9c8>] _requestfirmware+0xb8/0x608 [<00000000cad1aef7>] firmwarerequestnowarn+0x50/0x80 [<000000005011a682>] localpciprobe+0x48/0xd0 [<00000000077cd295>] pcideviceprobe+0xb4/0x200 [<0000000087184c94>] really_probe+0x150/0x2c0
The firmware memory was allocated in ath12kpciprobe(), but not freed in ath12kpciremove() in case ATH12KFLAGQMIFAIL bit is set. So call ath12kfw_unmap() to free the memory.
Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.2.0-02280-QCAHMTSWPLV1.0V2.0_SILICONZ-1
[
{
"signature_type": "Function",
"digest": {
"function_hash": "12304373347350925254042617629571331716",
"length": 597.0
},
"target": {
"file": "drivers/net/wireless/ath/ath12k/pci.c",
"function": "ath12k_pci_remove"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@52e3132e62c31b5ade43dc4495fa81175e6e8398",
"id": "CVE-2025-37744-15c3301e",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"268182022444806793155302200839336136182",
"321389156168122562279148571617726283148",
"126227203264955935356870365437921455520",
"144557752628111264426532752012702114406",
"231899259219186311293499702798782400319"
]
},
"target": {
"file": "drivers/net/wireless/ath/ath12k/pci.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1b24394ed5c8a8d8f7b9e3aa9044c31495d46f2e",
"id": "CVE-2025-37744-3ae3f66d",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"268182022444806793155302200839336136182",
"321389156168122562279148571617726283148",
"126227203264955935356870365437921455520",
"144557752628111264426532752012702114406",
"231899259219186311293499702798782400319"
]
},
"target": {
"file": "drivers/net/wireless/ath/ath12k/pci.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@52e3132e62c31b5ade43dc4495fa81175e6e8398",
"id": "CVE-2025-37744-402f8ccd",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "12304373347350925254042617629571331716",
"length": 597.0
},
"target": {
"file": "drivers/net/wireless/ath/ath12k/pci.c",
"function": "ath12k_pci_remove"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1b24394ed5c8a8d8f7b9e3aa9044c31495d46f2e",
"id": "CVE-2025-37744-b42cff25",
"deprecated": false,
"signature_version": "v1"
}
]