CVE-2025-38643 is a vulnerability in the Linux kernel's WiFi (cfg80211) component, specifically related to a missing lock in the cfg80211_check_and_end_cac() function. This oversight allows the cfg80211_propagate_cac_done_wk() worker to access wdev_chandef() without holding the necessary wiphy mutex, leading to a kernel warning. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring local privileges. The primary impact is a high availability impact, likely causing system instability or denial of service due to the kernel warning. There is no confidentiality or integrity impact. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.14.170, < 4.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 4.19.102, < 4.20CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.4.18, < 5.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5.1, < 6.6.118CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.57CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Xilinx) vulnerabilities
May 7, 2026Linux kernel (Azure FIPS) vulnerabilities
Apr 9, 2026Linux kernel (Raspberry Pi) vulnerabilities
Apr 1, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (AWS) vulnerabilities
Mar 23, 2026Linux kernel (Real-time) vulnerabilities
Mar 17, 2026Linux kernel (FIPS) vulnerabilities
Mar 16, 2026Linux kernel (NVIDIA) vulnerabilities
Mar 16, 2026Linux kernel vulnerabilities
Mar 16, 2026kernel: wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
Aug 22, 2025wifi: cfg80211: Add missing lock in cfg80211_check_and_end_cac()
Aug 12, 2025