Answer in brief
CVE-2025-37943 records a Unknown severity vulnerability in wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <7f1d986da5c6abb75ffe4d0d325fc9b341c41a1c || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <3abe15e756481c45f6acba3d476cb3ca4afc3b61 || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <6ee653194ddb83674913fd2727b8ecfae0597ade || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <50be1fb76556e80af9f5da80f28168b6c71bce58 || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <9a0dddfb30f120db3851627935851d262e4e7acb | 7f1d986da5c6abb75ffe4d0d325fc9b341c41a1c, 3abe15e756481c45f6acba3d476cb3ca4afc3b61, 6ee653194ddb83674913fd2727b8ecfae0597ade, 50be1fb76556e80af9f5da80f28168b6c71bce58, 9a0dddfb30f120db3851627935851d262e4e7acb |
| Linux/Linuxgeneric | 6.3 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-37943 records a Unknown severity vulnerability in wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <7f1d986da5c6abb75ffe4d0d325fc9b341c41a1c || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <3abe15e756481c45f6acba3d476cb3ca4afc3b61 || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <6ee653194ddb83674913fd2727b8ecfae0597ade || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <50be1fb76556e80af9f5da80f28168b6c71bce58 || >=d889913205cf7ebda905b1e62c5867ed4e39f6c2 <9a0dddfb30f120db3851627935851d262e4e7acb | 7f1d986da5c6abb75ffe4d0d325fc9b341c41a1c, 3abe15e756481c45f6acba3d476cb3ca4afc3b61, 6ee653194ddb83674913fd2727b8ecfae0597ade, 50be1fb76556e80af9f5da80f28168b6c71bce58, 9a0dddfb30f120db3851627935851d262e4e7acb |
| Linux/Linuxgeneric | 6.3 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1
Quoted source text, attributed separately from HOL analysis.