CVE-2025-38348 is a buffer overflow vulnerability in the Linux kernel's p54 Wi-Fi driver, specifically within the p54_rx_eeprom_readback() function. This flaw allows a malicious USB device, masquerading as an Intersil p54 Wi-Fi interface, to send a crafted eeprom_readback message with an oversized length, leading to data being copied beyond allocated memory. It primarily affects various Debian Linux kernel versions. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), this vulnerability requires local access (AV:L, PR:L) but has low attack complexity (AC:L). Successful exploitation can result in high impact on confidentiality, integrity, and availability (C:H, I:H, A:H), potentially leading to system crashes or arbitrary code execution. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available. Despite this, the vulnerability has garnered significant community attention with 2 mentions and 2 media articles, indicating awareness and discussion within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.28, < 5.4.295CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.239CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.186CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.142CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.95CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026kernel: wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
Jul 10, 2025wifi: p54: prevent buffer-overflow in p54_rx_eeprom_readback()
Jul 8, 2025