CVE-2025-38013: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: Set n_channels after allocating struct cfg80211_scan_request Make sure that n_channels is set after allocating the struct cfg80211_registered_device::int_scan_req member. Seen with syzkaller: UBSAN: array-index-out-of-bounds in net/mac80211/scan.c:1208:5 index 0 is out of range for type 'struct ieee80211_channel *[] __counted_by(n_channels)' (aka 'struct ieee80211_channel *[]') This was missed in the initial conversions because I failed to locate the allocation likely due to the "sizeof(void *)" not matching the "channels" array type.

Affected products

  • Linux Linux Kernel: from 6.6, before 6.6.92 (fixed in 6.6.92); from 6.7, before 6.12.30 (fixed in 6.12.30); from 6.13, before 6.14.8 (fixed in 6.14.8); version 6.15 only

Published 2025-06-18. Last modified 2026-06-17.