目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-38116— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.16% · P6

可能的 ATT&CK 技术 1AI

T1211 · Exploitation for Stealth

影响版本矩阵 6

厂商产品版本范围状态
LinuxLinux6f245ea0ec6c29b90c8fa4fdf6e178c646125d7e< 65e1b3404c211dcfaea02698539cdcd26647130faffected
6f245ea0ec6c29b90c8fa4fdf6e178c646125d7e< f3fe49dbddd73f0155a8935af47cb63693069dbeaffected
6.14affected
< 6.14unaffected
6.15.3≤ 6.15.*unaffected
6.16≤ *unaffected
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-38116 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
wifi: ath12k: fix uaf in ath12k_core_init()
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix uaf in ath12k_core_init() When the execution of ath12k_core_hw_group_assign() or ath12k_core_hw_group_create() fails, the registered notifier chain is not unregistered properly. Its memory is freed after rmmod, which may trigger to a use-after-free (UAF) issue if there is a subsequent access to this notifier chain. Fixes the issue by calling ath12k_core_panic_notifier_unregister() in failure cases. Call trace: notifier_chain_register+0x4c/0x1f0 (P) atomic_notifier_chain_register+0x38/0x68 ath12k_core_init+0x50/0x4e8 [ath12k] ath12k_pci_probe+0x5f8/0xc28 [ath12k] pci_device_probe+0xbc/0x1a8 really_probe+0xc8/0x3a0 __driver_probe_device+0x84/0x1b0 driver_probe_device+0x44/0x130 __driver_attach+0xcc/0x208 bus_for_each_dev+0x84/0x100 driver_attach+0x2c/0x40 bus_add_driver+0x130/0x260 driver_register+0x70/0x138 __pci_register_driver+0x68/0x80 ath12k_pci_init+0x30/0x68 [ath12k] ath12k_init+0x28/0x78 [ath12k] Tested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ath12k_core_init未正确注销通知链,可能导致释放后重用。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 6f245ea0ec6c29b90c8fa4fdf6e178c646125d7e ~ 65e1b3404c211dcfaea02698539cdcd26647130f -
LinuxLinux 6.14 -

二、漏洞 CVE-2025-38116 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-38116 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-07-03 · 共 78 条

CVE-2025-381239.8 CRITICALLinux kernel 安全漏洞
CVE-2025-381399.8 CRITICALLinux kernel 安全漏洞
CVE-2025-381209.4 CRITICALLinux kernel 安全漏洞
CVE-2025-381469.4 CRITICALLinux kernel 安全漏洞
CVE-2025-381417.8 HIGHLinux kernel 安全漏洞
CVE-2025-381687.8 HIGHLinux kernel 安全漏洞
CVE-2025-381627.8 HIGHLinux kernel 安全漏洞
CVE-2025-381547.8 HIGHLinux kernel 安全漏洞
CVE-2025-381067.8 HIGHLinux kernel 安全漏洞
CVE-2025-381507.8 HIGHLinux kernel 安全漏洞
CVE-2025-381087.8 HIGHLinux kernel 安全漏洞
CVE-2025-381107.8 HIGHLinux kernel 安全漏洞
CVE-2025-381117.8 HIGHLinux kernel 安全漏洞
CVE-2025-381077.8 HIGHLinux kernel 安全漏洞
CVE-2025-381157.8 HIGHLinux kernel 安全漏洞
CVE-2025-381177.8 HIGHLinux kernel 安全漏洞
CVE-2025-381187.8 HIGHLinux kernel 安全漏洞
CVE-2025-381337.8 HIGHLinux kernel 安全漏洞
CVE-2025-381297.8 HIGHLinux kernel 安全漏洞
CVE-2025-381277.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 78 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38116

暂无评论


发表评论