Answer in brief
CVE-2025-21906 records a Unknown severity vulnerability in wifi: iwlwifi: mvm: clean up ROC on failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <a88c18409b5d69f426d5acc583c053eac71756a3 || >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <d1a12fcb9051bbf38b2e5af310ffb102a0fab6f9 || >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <f9751163bffd3fe60794929829f810968c6de73d | a88c18409b5d69f426d5acc583c053eac71756a3, d1a12fcb9051bbf38b2e5af310ffb102a0fab6f9, f9751163bffd3fe60794929829f810968c6de73d |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anything at all because IWL_MVM_STATUS_ROC_P2P_RUNNING was never set. Set IWL_MVM_STATUS_ROC_P2P_RUNNING in the failure/stop path. If it started successfully before, it's already set, so that doesn't matter, and if it didn't start it needs to be set to clean up. Not doing so will lead to a WARN_ON() later on a fresh remain- on-channel, since the link is already active when activated as it was never deactivated.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-21906 records a Unknown severity vulnerability in wifi: iwlwifi: mvm: clean up ROC on failure. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <a88c18409b5d69f426d5acc583c053eac71756a3 || >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <d1a12fcb9051bbf38b2e5af310ffb102a0fab6f9 || >=35c1bbd93c4e6969b3ac238b48a8bdff3e223ed8 <f9751163bffd3fe60794929829f810968c6de73d | a88c18409b5d69f426d5acc583c053eac71756a3, d1a12fcb9051bbf38b2e5af310ffb102a0fab6f9, f9751163bffd3fe60794929829f810968c6de73d |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anything at all because IWL_MVM_STATUS_ROC_P2P_RUNNING was never set. Set IWL_MVM_STATUS_ROC_P2P_RUNNING in the failure/stop path. If it started successfully before, it's already set, so that doesn't matter, and if it didn't start it needs to be set to clean up. Not doing so will lead to a WARN_ON() later on a fresh remain- on-channel, since the link is already active when activated as it was never deactivated.
Quoted source text, attributed separately from HOL analysis.