CVE-2025-37744 is a memory leak vulnerability in the Linux kernel's ath12k Wi-Fi driver, specifically affecting the ath12k_pci_remove() function. This flaw occurs when firmware memory, allocated during ath12k_pci_probe(), is not properly freed if the ATH12K_FLAG_QMI_FAIL bit is set, leading to unreferenced memory objects. The vulnerability impacts Linux kernel versions utilizing the ath12k driver. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a local attack vector (AV:L) and low attack complexity (AC:L). Successful exploitation, requiring low privileges (PR:L), could lead to a high impact on availability (A:H) due to resource exhaustion, though it does not affect confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered moderate community attention with 3 mentions and significant media coverage across 3 articles, indicating awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.14, < 6.14.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026wifi: ath12k: fix memory leak in ath12k_pci_remove()
May 13, 2025kernel: wifi: ath12k: fix memory leak in ath12k_pci_remove()
May 1, 2025