CVE-2025-38645 is a NULL pointer dereference vulnerability in the Linux kernel's mlx5 network driver, affecting various Debian and Linux kernel versions. This flaw, rated Medium severity (CVSS 5.5), could lead to a denial of service (system crash) if the device memory allocation fails, requiring local access and low privileges to exploit. There is no known public exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog. However, the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite the lack of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4, < 5.15.190CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.148CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.102CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: net/mlx5: Check device memory pointer before usage
Aug 22, 2025net/mlx5: Check device memory pointer before usage
Aug 12, 2025