Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38348

21
FAUCET Score

CVE-2025-38348 is a buffer overflow vulnerability in the Linux kernel's p54 Wi-Fi driver, specifically within the p54_rx_eeprom_readback() function. This flaw allows a malicious USB device, masquerading as an Intersil p54 Wi-Fi interface, to send a crafted eeprom_readback message with an oversized length, leading to data being copied beyond allocated memory. It primarily affects various Debian Linux kernel versions. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), this vulnerability requires local access (AV:L, PR:L) but has low attack complexity (AC:L). Successful exploitation can result in high impact on confidentiality, integrity, and availability (C:H, I:H, A:H), potentially leading to system crashes or arbitrary code execution. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available. Despite this, the vulnerability has garnered significant community attention with 2 mentions and 2 media articles, indicating awareness and discussion within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.28, < 5.4.295CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.239CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.186CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.142CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.95CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 27th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

microsoftpatch availablevia msrc
Product: 19880-17084Fixed in: 6.6.96.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.92.2-2 on Azure Linux 3.0Fixed in: 6.6.96.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
grafanavendor investigatingvia llm_extracted
View patch

Vendor Advisories (8)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
redhatCVE-2025-38348

kernel: wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()

Jul 10, 2025
microsoft2025-Jul/CVE-2025-38348Moderate

wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()

Jul 8, 2025

References

git.kernel.org / stable/c/0e4dc150423b829c35cbcf399481ca11594fc036
Patch
git.kernel.org / stable/c/12134f79e53eb56b0b0b7447fa0c512acf6a8422
Patch
git.kernel.org / stable/c/1f7f8168abe8cbe845ab8bb557228d44784a6b57
Patch
git.kernel.org / stable/c/6d05390d20f110de37d051a3e063ef0a542d01fb
Patch
git.kernel.org / stable/c/714afb4c38edd19a057d519c1f9c5d164b43de94
Patch
git.kernel.org / stable/c/9701f842031b825e2fd5f22d064166f8f13f6e4d
Patch
git.kernel.org / stable/c/da1b9a55ff116cb040528ef664c70a4eec03ae99
Patch
git.kernel.org / stable/c/f39b2f8c1549a539846e083790fad396ef6cd802
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory