CVE-2025-38420 is a null-pointer dereference vulnerability in the Linux kernel's carl9170 Wi-Fi driver, affecting Debian and other Linux distributions. It occurs when the driver attempts to ping a device that failed to load firmware, leading to a crash. This vulnerability has a CVSS score of 5.5 MEDIUM, indicating a local attack vector with low complexity, requiring local privileges, and resulting in high availability impact (system crash). There is no evidence of active exploitation, and no public exploit code is available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.38, < 5.4.295CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.239CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.186CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.142CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.95CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026kernel: Linux kernel: Denial of Service in carl9170 Wi-Fi driver via ping to failed device
Jul 25, 2025wifi: carl9170: do not ping device which has failed to load firmware
Jul 8, 2025