Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38533

23
FAUCET Score

CVE-2025-38533 is a high-severity vulnerability in the Linux kernel's networking subsystem, specifically affecting the wx_rx_buffer structure's DMA handling. It arises from the use of an uninitialized 'dma' field, potentially leading to undefined behavior, including DMA errors or use-after-free conditions. The vulnerability has a CVSS score of 7.8 (HIGH), indicating a local attack vector with low complexity, and high impacts on confidentiality, integrity, and availability. While no active exploits or public exploit code (Metasploit, Nuclei, ExploitDB) are currently reported, the vulnerability has garnered community discussion and media coverage, suggesting awareness within the security community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.3, < 6.6.100CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.7, < 6.12.40CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.15.8CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
6.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 20th percentile among its peer group of 17,070 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-38533Moderate

kernel: net: libwx: fix the using of Rx buffer DMA

Aug 16, 2025
microsoft2025-Aug/CVE-2025-38533Important

net: libwx: fix the using of Rx buffer DMA

Aug 12, 2025

References

git.kernel.org / stable/c/027701180a7bcb64c42eab291133ef0c87b5b6c5
Patch
git.kernel.org / stable/c/05c37b574997892a40a0e9b9b88a481566b2367d
Patch
git.kernel.org / stable/c/5fd77cc6bd9b368431a815a780e407b7781bcca0
Patch
git.kernel.org / stable/c/ba7c793f96c1c2b944bb6f423d7243f3afc30fe9
Patch