CVE-2024-57995 is a moderate-severity use-after-free flaw in the Linux kernel's Qualcomm ath12k Wi-Fi driver, affecting ath12k_mac_assign_vif_to_vdev(). An arvif object created on another radio can be freed by ath12k_mac_unassign_link_vif() and subsequently dereferenced. The vulnerability was introduced in Linux 6.10 and fixed upstream in stable kernel 6.13.2 and 6.14-rc1; the Linux kernel CVE team recommends upgrading to a current stable release rather than applying the isolated fix.
Red Hat assigned the vulnerability a CVSS v3.1 score of 6.7 and states exploitation requires local root privileges. Fixes are available for RHEL 9 and RHEL 10 through advisories RHSA-2025:20518 and RHSA-2025:20095; RHEL 6, 7, 7 kernel-rt, 8, and 8 kernel-rt are not affected, while RHEL 9 kernel-rt is listed as will not fix.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20518 for the RHEL 9 kernel and RHSA-2025:20095 for the RHEL 10 kernel, addressing the ath12k use-after-free vulnerability.
The Linux kernel CVE team assigned CVE-2024-57995 to the ath12k use-after-free issue. Fixes were included in Linux 6.13.2 and 6.14-rc1 by moving the affected check until after arvif is reassigned.
The read-after-free condition in ath12k_mac_assign_vif_to_vdev() was introduced in Linux kernel 6.10. It can occur when ath12k_mac_unassign_link_vif() frees an arvif created on another radio before subsequent code reads it.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.