CVE & CISA-KEV Catalog

CVE-2025-38601

HIGH
8.8
CVSS v3
NVD

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: clear initialized flag for deinit-ed srng lists In a number of cases we see kernel panics on resume due to ath11k kernel page fault, which happens under the following circumstances: 1) First ath11k_hal_dump_srng_stats() call Last interrupt received for each group: ath11k_pci 0000:01:00.0: group_id 0 22511ms before ath11k_pci 0000:01:00.0: group_id 1 14440788ms before [..] ath11k_pci 0000:01:00.0: failed to receive control response completion, polling.. ath11k_pci 0000:01:00.0: Service connect timeout ath11k_pci 0000:01:00.0: failed to connect to HTT: -110 ath11k_pci 0000:01:00.0: failed to start core: -110 ath11k_pci 0000:01:00.0: firmware crashed: MHI_CB_EE_RDDM ath11k_pci 0000:01:00.0: already resetting count 2 ath11k_pci 0000:01:00.0: failed to wait wlan mode request (mode 4): -110 ath11k_pci 0000:01:00.0: qmi failed to send wlan mode off: -110 ath11k_pci 0000:01:00.0: failed to reconfigure driver on crash recovery [..] 2) At this point reconfiguration fails (we have 2 resets) and ath11k_core_reconfigure_on_crash() calls ath11k_hal_srng_deinit() which destroys srng lists. However, it does not reset per-list ->initialized flag. 3) Second ath11k_hal_dump_srng_stats() call sees stale ->initialized flag and attempts to dump srng stats: Last interrupt received for each group: ath11k_pci 0000:01:00.0: group_id 0 66785ms before ath11k_pci 0000:01:00.0: group_id 1 14485062ms before ath11k_pci 0000:01:00.0: group_id 2 14485062ms before ath11k_pci 0000:01:00.0: group_id 3 14485062ms before ath11k_pci 0000:01:00.0: group_id 4 14780845ms before ath11k_pci 0000:01:00.0: group_id 5 14780845ms before ath11k_pci 0000:01:00.0: group_id 6 14485062ms before ath11k_pci 0000:01:00.0: group_id 7 66814ms before ath11k_pci 0000:01:00.0: group_id 8 68997ms before ath11k_pci 0000:01:00.0: group_id 9 67588ms before ath11k_pci 0000:01:00.0: group_id 10 69511ms before BUG: unable to handle page fault for address: ffffa007404eb010 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 100000067 P4D 100000067 PUD 10022d067 PMD 100b01067 PTE 0 Oops: 0000 [#1] PREEMPT SMP NOPTI RIP: 0010:ath11k_hal_dump_srng_stats+0x2b4/0x3b0 [ath11k] Call Trace: <TASK> ? __die_body+0xae/0xb0 ? page_fault_oops+0x381/0x3e0 ? exc_page_fault+0x69/0xa0 ? asm_exc_page_fault+0x22/0x30 ? ath11k_hal_dump_srng_stats+0x2b4/0x3b0 [ath11k (HASH:6cea 4)] ath11k_qmi_driver_event_work+0xbd/0x1050 [ath11k (HASH:6cea 4)] worker_thread+0x389/0x930 kthread+0x149/0x170 Clear per-list ->initialized flag in ath11k_hal_srng_deinit().

How to fix

Remediation Available
linuxDebian
Fixed in:5.10.244-1CVE-2025-38601
Fixed in:6.1.148-1CVE-2025-38601
Fixed in:6.12.43-1CVE-2025-38601
Fixed in:6.16.3-1CVE-2025-38601
linuxUbuntu
Fixed in:5.15.0-163.173USN-7909-1
Fixed in:6.8.0-100.100USN-8028-1
linux-awsUbuntu
Fixed in:5.15.0-1097.104USN-7909-1
Fixed in:6.8.0-1046.49USN-8028-5
linux-aws-5.15Ubuntu
Fixed in:5.15.0-1097.104~20.04.1USN-7909-1
linux-aws-6.14Ubuntu
Fixed in:6.14.0-1017.17~24.04.1USN-7879-3
linux-aws-6.8Ubuntu
Fixed in:6.8.0-1046.49~22.04.1USN-8028-5
linux-aws-fipsUbuntu
Fixed in:5.15.0-1097.104+fips1USN-7909-3
Fixed in:6.8.0-1046.49+fips1USN-8028-4
linux-azureUbuntu
Fixed in:5.15.0-1101.110USN-7910-2
Fixed in:6.8.0-1046.52USN-8074-1
linux-azure-5.15Ubuntu
Fixed in:5.15.0-1102.111~20.04.1USN-7938-1
linux-azure-6.14Ubuntu
Fixed in:6.14.0-1017.17~24.04.1USN-7934-1
linux-azure-6.8Ubuntu
Fixed in:6.8.0-1051.57~22.04.1USN-8126-1
linux-azure-fipsUbuntu
Fixed in:5.15.0-1101.110+fips1USN-7910-1
Fixed in:6.8.0-1046.52+fips1USN-8074-2
linux-fipsUbuntu
Fixed in:5.15.0-163.173+fips1USN-7909-3
Fixed in:6.8.0-100.100+fips1USN-8028-4
linux-gcpUbuntu
Fixed in:5.15.0-1097.106USN-7909-4
Fixed in:6.8.0-1047.50USN-8031-3
linux-gcp-5.15Ubuntu
Fixed in:5.15.0-1097.106~20.04.1USN-7909-1
linux-gcp-6.14Ubuntu
Fixed in:6.14.0-1020.21~24.04.1USN-7879-4
linux-gcp-6.8Ubuntu
Fixed in:6.8.0-1047.50~22.04.2USN-8031-1
linux-gcp-fipsUbuntu
Fixed in:5.15.0-1097.106+fips1USN-7909-3
Fixed in:6.8.0-1047.50+fips1USN-8031-2
linux-gkeUbuntu
Fixed in:5.15.0-1093.99USN-7909-4
Fixed in:6.8.0-1043.48USN-8031-3
linux-gkeopUbuntu
Fixed in:5.15.0-1080.88USN-7909-4
Fixed in:6.8.0-1030.33USN-8028-5
linux-hwe-5.15Ubuntu
Fixed in:5.15.0-163.173~20.04.1USN-7909-1
linux-hwe-6.14Ubuntu
Fixed in:6.14.0-36.36~24.04.1USN-7879-1
linux-hwe-6.8Ubuntu
Fixed in:6.8.0-100.100~22.04.1USN-8028-6
linux-ibmUbuntu
Fixed in:5.15.0-1091.94USN-7909-1
Fixed in:6.8.0-1044.44USN-8028-8
linux-ibm-5.15Ubuntu
Fixed in:5.15.0-1091.94~20.04.1USN-7909-1
linux-ibm-6.8Ubuntu
Fixed in:6.8.0-1044.44~22.04.1USN-8028-8
linux-image-5.15.0-1038-nvidia-tegra-igxUbuntu
Fixed in:5.15.0-1038.38USN-7909-1
linux-image-5.15.0-1038-nvidia-tegra-igx-rtUbuntu
Fixed in:5.15.0-1038.38USN-7909-1
linux-image-5.15.0-1049-nvidia-tegraUbuntu
Fixed in:5.15.0-1049.49~20.04.1USN-7909-1
Fixed in:5.15.0-1049.49USN-7909-1
linux-image-5.15.0-1049-nvidia-tegra-rtUbuntu
Fixed in:5.15.0-1049.49~20.04.1USN-7909-1
Fixed in:5.15.0-1049.49USN-7909-1

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

0.23%probability of exploitation in 30 days
14thpercentile

Low risk: more likely to be exploited than 14% of all known CVEs.

References

Related Vulnerabilities

Other CWE-909 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2018-14647High7.511%-Fix
CVE-2019-9639High7.58.2%-Fix
CVE-2018-10811High7.56.2%-Fix
CVE-2020-12352Medium6.55.7%-Fix
CVE-2019-3804High7.54.9%-Fix
CVE-2020-16932High7.84.8%--

Common questions

How do I fix CVE-2025-38601?

Published advisories record a fix for 271 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2025-38601 being actively exploited?

Not that we know of. CVE-2025-38601 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 0.23% is the estimated probability that it will be exploited in the next 30 days. That is higher than 14% of all scored CVEs.

How severe is CVE-2025-38601?

CVE-2025-38601 has a CVSS v3 base score of 8.8, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2025-38601 affect?

Published advisories record a fix for linux (Debian), linux (Ubuntu), linux-aws (Ubuntu), linux-aws-5.15 (Ubuntu), and 267 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2025-38601
CVE-2025-38601 severity badge

Markdown

[![CVE-2025-38601](https://tridentstack.com/cve/badge/CVE-2025-38601.svg)](https://tridentstack.com/cve/CVE-2025-38601)

HTML

<a href="https://tridentstack.com/cve/CVE-2025-38601"><img src="https://tridentstack.com/cve/badge/CVE-2025-38601.svg" alt="CVE-2025-38601"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

See how it worksStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-30.