Review reviewHigh

CVE-2025-38512

Linux Linux, linux kernel, debian linux

In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This patch is a mitigation to prevent the A-MSDU spoofing vulnerability for mesh networks. The initial update to the IEEE 802.11 standard, in response to the FragAttacks, missed this case (CVE-2025-27558). It can be considered a variant of CVE-2020-24588 but for mesh networks. This patch tries to detect if a standard MSDU was turned into an A-MSDU by an adversary. This is done by parsing a received A-MSDU as a standard MSDU, calculating the length of the Mesh Control header, and...

CVSS
7.8
EPSS
0.22%
12.8% percentile
CISA KEV
Not listed
Published
2025.08.16
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.22%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: wifi: prevent A-MSDU attacks in mesh networks This patch is a mitigation to prevent the A-MSDU spoofing vulnerability for mesh networks. The initial update to the IEEE 802.11 standard, in response to the FragAttacks, missed this case (CVE-2025-27558). It can be considered a variant of CVE-2020-24588 but for mesh networks. This patch tries to detect if a standard MSDU was turned into an A-MSDU by an adversary. This is done by parsing a received A-MSDU as a standard MSDU, calculating the length of the Mesh Control header, and...

Affected product and versions

Product
Linux Linux, linux kernel, debian linux
Affected versions
>= 79720743421753ff72bfa0d79976c534645b81c1 < e2c8a3c0388aef6bfc4aabfba07bc7dff16eea80, >= 986e43b19ae9176093da35e0a844e65c8bf9ede7 < ec6392061de6681148b63ee6c8744da833498cdd, >= 986e43b19ae9176093da35e0a844e65c8bf9ede7 < e01851f6e9a665a6011b14714b271d3e6b0b8d32, >= 986e43b19ae9176093da35e0a844e65c8bf9ede7 < 6e3b09402cc6c3e3474fa548e8adf6897dda05de, >= 986e43b19ae9176093da35e0a844e65c8bf9ede7 < 737bb912ebbe4571195c56eba557c4d7315b26fb, >= 6.1.107 < 6.1.146, >= 6.3, >= 6.3 < 6.6.99, >= 6.7 < 6.12.39, >= 6.13 < 6.15.7, 6.16, 11.0
Fixed versions
6.1.146, 6.6.99, 6.12.39, 6.15.7

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, linux kernel, debian linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2025-38512 — Linux Linux, linux kernel, debian linux | SECUFOCUS NOW