🛡️ CVE-2025-40321 — kernel

⚪ Unknown ✅ No Known Exploit NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode

In the Linux kernel, the following vulnerability has been resolved:

wifi: brcmfmac: fix crash while sending Action Frames in standalone AP Mode

Currently, whenever there is a need to transmit an Action frame,

the brcmfmac driver always uses the P2P vif to send the "actframe" IOVAR to

firmware. The P2P interfaces were available when wpa_supplicant is managing

the wlan interface.

However, the P2P interfaces are not created/initialized when only hostapd

is managing the wlan interface. And if hostapd receives an ANQP Query REQ

Action frame even from an un-associated STA, the brcmfmac driver tries

to use an uninitialized P2P vif pointer for sending the IOVAR to firmware.

This NULL pointer dereferencing triggers a driver crash.

[ 1417.074538] Unable to handle kernel NULL pointer dereference at virtual

address 0000000000000000

[...]

[ 1417.075188] Hardware name: Raspberry Pi 4 Model B Rev 1.5 (DT)

[...]

[ 1417.075653] Call trace:

[ 1417.075662] brcmf_p2p_send_action_frame+0x23c/0xc58 [brcmfmac]

[ 1417.075738] brcmf_cfg80211_mgmt_tx+0x304/0x5c0 [brcmfmac]

[ 1417.075810] cfg80211_mlme_mgmt_tx+0x1b0/0x428 [cfg80211]

[ 1417.076067] nl80211_tx_mgmt+0x238/0x388 [cfg80211]

[ 1417.076281] genl_family_rcv_msg_doit+0xe0/0x158

[ 1417.076302] genl_rcv_msg+0x220/0x2a0

[ 1417.076317] netlink_rcv_skb+0x68/0x140

[ 1417.076330] genl_rcv+0x40/0x60

[ 1417.076343] netlink_unicast+0x330/0x3b8

[ 1417.076357] netlink_sendmsg+0x19c/0x3f8

[ 1417.076370] __sock_sendmsg+0x64/0xc0

[ 1417.076391] ____sys_sendmsg+0x268/0x2a0

[ 1417.076408] ___sys_sendmsg+0xb8/0x118

[ 1417.076427] __sys_sendmsg+0x90/0xf8

[ 1417.076445] __arm64_sys_sendmsg+0x2c/0x40

[ 1417.076465] invoke_syscall+0x50/0x120

[ 1417.076486] el0_svc_common.constprop.0+0x48/0xf0

[ 1417.076506] do_el0_svc+0x24/0x38

[ 1417.076525] el0_svc+0x30/0x100

[ 1417.076548] el0t_64_sync_handler+0x100/0x130

[ 1417.076569] el0t_64_sync+0x190/0x198

[ 1417.076589] Code: f9401e80 aa1603e2 f9403be1 5280e483 (f9400000)

Fix this, by always using the vif corresponding to the wdev on which the

Action frame Transmission request was initiated by the userspace. This way,

even if P2P vif is not available, the IOVAR is sent to firmware on AP vif

and the ANQP Query RESP Action frame is transmitted without crashing the

driver.

Move init_completion() for "send_af_done" from brcmf_p2p_create_p2pdev()

to brcmf_p2p_attach(). Because the former function would not get executed

when only hostapd is managing wlan interface, and it is not safe to do

reinit_completion() later in brcmf_p2p_tx_action_frame(), without any prior

init_completion().

And in the brcmf_p2p_tx_action_frame() function, the condition check for

P2P Presence response frame is not needed, since the wpa_supplicant is

properly sending the P2P Presense Response frame on the P2P-GO vif instead

of the P2P-Device vif.

[Cc stable]

Affected software

CVE-2025-40321 is recorded against 2 packages.

  • kernel (from 6.13.0 up to 6.17.8)
  • unknown

Timeline and source

Published on 8 December 2025 and last revised on 15 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
git.kernel.org (Web)
github.com (Advisory)
nvd.nist.gov (Advisory)
git.kernel.org (Package)

CVE-2025-40321 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source NVD
Published 2025-12-08
Updated 2026-08-12
Modified 2026-07-15
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.13.0 6.17.8
unknown

References

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2025-40321?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2025-40321 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025