In the Linux kernel, the following vulnerability has been resolved:
wifi: carl9170: do not ping device which has failed to load firmware
Syzkaller reports [1, 2] crashes caused by an attempts to ping the device which has failed to load firmware. Since such a device doesn't pass 'ieee80211registerhw()', an internal workqueue managed by 'ieee80211queuework()' is not yet created and an attempt to queue work on it causes null-ptr-deref.
[1] https://syzkaller.appspot.com/bug?extid=9a4aec827829942045ff [2] https://syzkaller.appspot.com/bug?extid=0d8afba53e8fb2633217
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38420.json"
}[
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2025-38420-11d9913d",
"target": {
"file": "drivers/net/wireless/ath/carl9170/usb.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"333115340860920092916279109980550821310",
"182368401836441409053704254397292240750",
"152541347048193647046090482806305008491",
"305522776919611031726284281929919969092"
]
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15d25307692312cec4b57052da73387f91a2e870"
},
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2025-38420-5cda7acb",
"target": {
"file": "drivers/net/wireless/ath/carl9170/usb.c",
"function": "carl9170_usb_rx_complete"
},
"digest": {
"length": 704.0,
"function_hash": "14036521764660076408407150516322362821"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@15d25307692312cec4b57052da73387f91a2e870"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38420.json"