Answer in brief
CVE-2025-38604 records a Unknown severity vulnerability in wifi: rtl818x: Kill URBs before clearing tx status queue. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38604 records a Unknown severity vulnerability in wifi: rtl818x: Kill URBs before clearing tx status queue. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <e64732ebff9e24258e7326f07adbe2f2b990daf8 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <789415771422f4fb9f444044f86ecfaec55df1bd || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <c73c773b09e313278f9b960303a2809b8440bac6 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <8c767727f331fb9455b0f81daad832b5925688cb || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <14ca6952691fa8cc91e7644512e6ff24a595283f || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <7858a95566f4ebf59524666683d2dcdba3fca968 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <c51a45ad9070a6d296174fcbe5c466352836c12b || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <81cfe34d0630de4e23ae804dcc08fb6f861dc37d || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <16d8fd74dbfca0ea58645cd2fca13be10cae3cdd | e64732ebff9e24258e7326f07adbe2f2b990daf8, 789415771422f4fb9f444044f86ecfaec55df1bd, c73c773b09e313278f9b960303a2809b8440bac6, 8c767727f331fb9455b0f81daad832b5925688cb, 14ca6952691fa8cc91e7644512e6ff24a595283f, 7858a95566f4ebf59524666683d2dcdba3fca968, c51a45ad9070a6d296174fcbe5c466352836c12b, 81cfe34d0630de4e23ae804dcc08fb6f861dc37d, 16d8fd74dbfca0ea58645cd2fca13be10cae3cdd |
| Linux/Linuxgeneric | 2.6.29 | Not reported |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Kill URBs before clearing tx status queue In rtl8187_stop() move the call of usb_kill_anchored_urbs() before clearing b_tx_status.queue. This change prevents callbacks from using already freed skb due to anchor was not killed before freeing such skb. BUG: kernel NULL pointer dereference, address: 0000000000000080 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Not tainted 6.15.0 #8 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 0.0.0 02/06/2015 RIP: 0010:ieee80211_tx_status_irqsafe+0x21/0xc0 [mac80211] Call Trace: <IRQ> rtl8187_tx_cb+0x116/0x150 [rtl8187] __usb_hcd_giveback_urb+0x9d/0x120 usb_giveback_urb_bh+0xbb/0x140 process_one_work+0x19b/0x3c0 bh_worker+0x1a7/0x210 tasklet_action+0x10/0x30 handle_softirqs+0xf0/0x340 __irq_exit_rcu+0xcd/0xf0 common_interrupt+0x85/0xa0 </IRQ> Tested on RTL8187BvE device. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <e64732ebff9e24258e7326f07adbe2f2b990daf8 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <789415771422f4fb9f444044f86ecfaec55df1bd || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <c73c773b09e313278f9b960303a2809b8440bac6 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <8c767727f331fb9455b0f81daad832b5925688cb || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <14ca6952691fa8cc91e7644512e6ff24a595283f || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <7858a95566f4ebf59524666683d2dcdba3fca968 || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <c51a45ad9070a6d296174fcbe5c466352836c12b || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <81cfe34d0630de4e23ae804dcc08fb6f861dc37d || >=c1db52b9d27ee6e15a7136e67e4a21dc916cd07f <16d8fd74dbfca0ea58645cd2fca13be10cae3cdd | e64732ebff9e24258e7326f07adbe2f2b990daf8, 789415771422f4fb9f444044f86ecfaec55df1bd, c73c773b09e313278f9b960303a2809b8440bac6, 8c767727f331fb9455b0f81daad832b5925688cb, 14ca6952691fa8cc91e7644512e6ff24a595283f, 7858a95566f4ebf59524666683d2dcdba3fca968, c51a45ad9070a6d296174fcbe5c466352836c12b, 81cfe34d0630de4e23ae804dcc08fb6f861dc37d, 16d8fd74dbfca0ea58645cd2fca13be10cae3cdd |
| Linux/Linuxgeneric | 2.6.29 | Not reported |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: wifi: rtl818x: Kill URBs before clearing tx status queue In rtl8187_stop() move the call of usb_kill_anchored_urbs() before clearing b_tx_status.queue. This change prevents callbacks from using already freed skb due to anchor was not killed before freeing such skb. BUG: kernel NULL pointer dereference, address: 0000000000000080 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP NOPTI CPU: 7 UID: 0 PID: 0 Comm: swapper/7 Not tainted 6.15.0 #8 PREEMPT(voluntary) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 0.0.0 02/06/2015 RIP: 0010:ieee80211_tx_status_irqsafe+0x21/0xc0 [mac80211] Call Trace: <IRQ> rtl8187_tx_cb+0x116/0x150 [rtl8187] __usb_hcd_giveback_urb+0x9d/0x120 usb_giveback_urb_bh+0xbb/0x140 process_one_work+0x19b/0x3c0 bh_worker+0x1a7/0x210 tasklet_action+0x10/0x30 handle_softirqs+0xf0/0x340 __irq_exit_rcu+0xcd/0xf0 common_interrupt+0x85/0xa0 </IRQ> Tested on RTL8187BvE device. Found by Linux Verification Center (linuxtesting.org) with SVACE.
Quoted source text, attributed separately from HOL analysis.