Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38656

24
FAUCET Score

CVE-2025-38656 is a high-severity vulnerability (CVSS 7.8) in the Linux kernel's iwlwifi driver, specifically affecting the iwl_op_mode_dvm_start() function. It involves an incorrect error code handling that can lead to a use-after-free condition, potentially allowing an attacker with local privileges to achieve high impact on confidentiality, integrity, and availability. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.4.297, < 5.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.10.241, < 5.11CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.15.190, < 5.16CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.1.148, < 6.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6.102, < 6.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 24th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (2)

redhatCVE-2025-38656

kernel: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()

Aug 22, 2025
microsoft2025-Aug/CVE-2025-38656Moderate

wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()

Aug 12, 2025

References

git.kernel.org / stable/c/1d068272c21d886d06526454b68368100ba0a720
Patch
git.kernel.org / stable/c/991e2066f6009d3cb898413058c62dbcc92bd6d2
Patch
git.kernel.org / stable/c/cf80c02a9fdb6c5bc8508beb6a0f6a1294fc32f6
Patch