CVE-2025-38646 is a NULL pointer dereference vulnerability in the Linux kernel's rtw89 Wi-Fi driver. It affects systems running the Linux kernel, specifically when the driver encounters a problematic RX report on an unsupported 6 GHz band, leading to a system crash. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low attack complexity, requiring local privileges. The primary impact is a denial of service (system crash), with no impact on confidentiality or integrity. There is no evidence of active exploitation, nor are there publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. While there are a few community discussions and media articles, these primarily relate to Ubuntu security advisories, not widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.4, < 6.6.102CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.42CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.16, < 6.16.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026kernel: wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band
Aug 22, 2025wifi: rtw89: avoid NULL dereference when RX problematic packet on unsupported 6 GHz band
Aug 12, 2025