CVE-2025-39732 is a medium-severity vulnerability in the Linux kernel's ath11k Wi-Fi driver, specifically affecting the ath11k_mac_op_set_bitrate_mask() function. The flaw, categorized as a "sleeping-in-atomic" bug, occurs because ath11k_mac_disable_peer_fixed_rate() can sleep when called from an atomic context, leading to system instability and potential denial of service. With a CVSS score of 5.5, this local vulnerability requires low privileges and low attack complexity, impacting system availability. There is currently no evidence of active exploitation, no public exploit code available, and it has garnered limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6, < 6.12.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.16, < 6.16.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
Sep 9, 2025kernel: wifi: ath11k: fix sleeping-in-atomic in ath11k_mac_op_set_bitrate_mask()
Sep 7, 2025