← All CVEs

CVE-2025-38533

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_rx_buffer structure contained two DMA address fields: 'dma' and 'page_dma'. However, only 'page_dma' was actually initialized and used to program the Rx descriptor. But 'dma' was uninitialized and used in some paths. This could lead to undefined behavior, including DMA errors or use-after-free, if the uninitialized 'dma' was used. Althrough such error has not yet occurred, it is worth fixing in the code.

9.8
CVSS
0.3%
EPSS (exploit prob.)
23rd
EPSS percentile
2025-08-16
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 6.3, < 6.6.100
linuxlinux_kernel>= 6.7, < 6.12.40
linuxlinux_kernel>= 6.13, < 6.15.8
linuxlinux_kernel6.16
linuxlinux_kernel6.16
linuxlinux_kernel6.16
linuxlinux_kernel6.16
linuxlinux_kernel6.16
linuxlinux_kernel6.16

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-38533