Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38693

20
FAUCET Score

CVE-2025-38693 is a null-pointer dereference vulnerability in the Linux kernel's w7090p DVB frontend driver, affecting Debian and other Linux kernel distributions. This flaw, rated Medium severity (CVSS 5.5), allows a local attacker with low privileges to cause a denial of service (system crash) due to insufficient input validation in the w7090p_tuner_write_serpar and w7090p_tuner_read_serpar functions. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the security community. It is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.6.39, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 33rd percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (12)

microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0Fixed in: 5.15.200.1-1
microsoftpatch availablevia msrc
Product: 17087-17086Fixed in: 5.15.200.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
microsoft2025-Sep/CVE-2025-38693Moderate

media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar

Sep 9, 2025
redhatCVE-2025-38693Low

kernel: media: dvb-frontends: w7090p: fix null-ptr-deref in w7090p_tuner_write_serpar and w7090p_tuner_read_serpar

Sep 4, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
git.kernel.org / stable/c/17b30e5ded062bd74f8ca6f317e1d415a8680665
Patch
git.kernel.org / stable/c/39b06b93f24dff923c4183d564ed28c039150554
Patch
git.kernel.org / stable/c/454a443eaa792c8865c861a282fe6d4f596abc3a
Patch
git.kernel.org / stable/c/6bbaec6a036940e22318f0454b50b8000845ab59
Patch
git.kernel.org / stable/c/7a41ecfc3415ebe3b4c44f96b3337691dcf431a3
Patch
git.kernel.org / stable/c/99690a494d91a0dc86cebd628da4c62c40552bcb
Patch
git.kernel.org / stable/c/b3d77a3fc71c084575d3df4ec6544b3fb6ce587d
git.kernel.org / stable/c/ed0234c8458b3149f15e496b48a1c9874dd24a1b
Patch
git.kernel.org / stable/c/f98132a59ccc59a8b97987363bc99c8968934756
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Third Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory