{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.17.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  wifi: ath12k: Fix peer lookup in ath12k_dp_mon_rx_deliver_msdu()  In ath12k_dp_mon_rx_deliver_msdu(), peer lookup fails because rxcb-\u003epeer_id is not updated with a valid value. This is expected in monitor mode, where RX frames bypass the regular RX descriptor path that typically sets rxcb-\u003epeer_id. As a result, the peer is NULL, and link_id and link_valid fields in the RX status are not populated. This leads to a WARN_ON in mac80211 when it receives data frame from an associated station with invalid link_id.  Fix this potential issue by using ppduinfo-\u003epeer_id, which holds the correct peer id for the received frame. This ensures that the peer is correctly found and the associated link metadata is updated accordingly.  Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.4.1-00199-QCAHKSWPL_SILICONZ-1",
  "id": "DEBIAN-CVE-2025-40131",
  "modified": "2026-09-01T19:48:26.360486735Z",
  "published": "2025-11-12T11:15:42.753Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2025-40131"
    }
  ],
  "upstream": [
    "CVE-2025-40131"
  ]
}