CVE Database
/

CVE-2025-39864

Back to search

CVE-2025-39864

Published: Sep 19, 2025

Modified: May 12, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: fix use-after-free in cmp_bss() Following bss_free() quirk introduced in commit 776b3580178f ("cfg80211: track hidden SSID networks properly"), adjust cfg80211_update_known_bss() to free the last beacon frame elements only if they're not shared via the corresponding 'hidden_beacon_bss' pointer.

VendorProductVersions

Linux

Linux

affected
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6 - < a8bb681e879ca3c9f722aa08d3d7ae41c42a8807
affected
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6 - < a97a9791e455bb0cd5e7a38b5abcb05523d4e21c
affected
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6 - < ff040562c10a540b8d851f7f4145fa112977f853
affected
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6 - < 6854476d9e1aeaaf05ebc98d610061c2075db07d
affected
3ab8227d3e7d1d2bf1829675d3197e3cb600e9f6 - < b7d08929178c16398278613df07ad65cf63cce9d

+3 more versions

Linux

Linux

affected
5.4
unaffected
0 - < 5.4
unaffected
5.4.299 - <= 5.4.*
unaffected
5.10.243 - <= 5.10.*
unaffected
5.15.192 - <= 5.15.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now