cbcvebase.
CVE-2025-38533
published 2025-08-16

CVE-2025-38533: In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_rx_buffer structure contained two DMA…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_rx_buffer structure contained two DMA address fields: 'dma' and 'page_dma'. However, only 'page_dma' was actually initialized and used to program the Rx descriptor. But 'dma' was uninitialized and used in some paths. This could lead to undefined behavior, including DMA errors or use-after-free, if the uninitialized 'dma' was used. Althrough such error has not yet occurred, it is worth fixing in the code.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 3c47e8ae113a68da47987750d9896e325d0aeedd < 027701180a7bcb64c42eab291133ef0c87b5b6c5027701180a7bcb64c42eab291133ef0c87b5b6c5
linuxlinux>= 3c47e8ae113a68da47987750d9896e325d0aeedd < ba7c793f96c1c2b944bb6f423d7243f3afc30fe9ba7c793f96c1c2b944bb6f423d7243f3afc30fe9
linuxlinux>= 3c47e8ae113a68da47987750d9896e325d0aeedd < 05c37b574997892a40a0e9b9b88a481566b2367d05c37b574997892a40a0e9b9b88a481566b2367d
linuxlinux>= 3c47e8ae113a68da47987750d9896e325d0aeedd < 5fd77cc6bd9b368431a815a780e407b7781bcca05fd77cc6bd9b368431a815a780e407b7781bcca0
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.41-16.12.41-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.15.86.15.8
linuxlinux_kernel>= 6.3 < 6.6.1006.6.100
linuxlinux_kernel>= 6.7 < 6.12.406.12.40
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_binutils_2.37-4_on_cbl_mariner_2.0
msrccm1_binutils_2.36.1-3_on_cbl_mariner_1.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.