CVE-2025-38533 is a high-severity vulnerability in the Linux kernel's networking subsystem, specifically affecting the wx_rx_buffer structure's DMA handling. It arises from the use of an uninitialized 'dma' field, potentially leading to undefined behavior, including DMA errors or use-after-free conditions. The vulnerability has a CVSS score of 7.8 (HIGH), indicating a local attack vector with low complexity, and high impacts on confidentiality, integrity, and availability. While no active exploits or public exploit code (Metasploit, Nuclei, ExploitDB) are currently reported, the vulnerability has garnered community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.3, < 6.6.100CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.40CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:* | ||
6.16CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: net: libwx: fix the using of Rx buffer DMA
Aug 16, 2025net: libwx: fix the using of Rx buffer DMA
Aug 12, 2025