# CVE-2025-39991

## Summary

- **CVE ID:** CVE-2025-39991
- **Severity:** UNKNOWN
- **CVSS Score:** 1.51
- **CWE:** N/A
- **Published:** Oct 15, 2025
- **Last Modified:** Sep 17, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

wifi: ath11k: fix NULL dereference in ath11k_qmi_m3_load()

If ab->fw.m3_data points to data, then fw pointer remains null.
Further, if m3_mem is not allocated, then fw is dereferenced to be
passed to ath11k_err function.

Replace fw->size by m3_len.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

## Affected Products

- Linux — Linux (7db88b962f06a52af5e9a32971012e8f3427cec0)
- Linux — Linux (6.7)
- Linux — Linux (0)
- Linux — Linux (6.12.51)
- Linux — Linux (6.16.11)
- Linux — Linux (6.17.1)
- Linux — Linux (6.18)
- Linux — Linux (98e373dc08187c3f1cd97342b369fa2b0f24005e)

## References

- [CNA](https://git.kernel.org/stable/c/1f52119809b76d43759fc47da1cf708690b740a1)
- [CNA](https://git.kernel.org/stable/c/888830b2cbc035838bebefe94502976da94332a5)
- [CNA](https://git.kernel.org/stable/c/500fcc31e488d798937a23dbb1f62db46820c5b2)
- [CNA](https://git.kernel.org/stable/c/3fd2ef2ae2b5c955584a3bee8e83ae7d7a98f782)
- [CNA](https://git.kernel.org/stable/c/7554d498e4283c3b4559795abd175eb24a84f47f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._