CVE-2025-38533

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
16/08/2025
Last modified:
18/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> net: libwx: fix the using of Rx buffer DMA<br /> <br /> The wx_rx_buffer structure contained two DMA address fields: &amp;#39;dma&amp;#39; and<br /> &amp;#39;page_dma&amp;#39;. However, only &amp;#39;page_dma&amp;#39; was actually initialized and used<br /> to program the Rx descriptor. But &amp;#39;dma&amp;#39; was uninitialized and used in<br /> some paths.<br /> <br /> This could lead to undefined behavior, including DMA errors or<br /> use-after-free, if the uninitialized &amp;#39;dma&amp;#39; was used. Althrough such<br /> error has not yet occurred, it is worth fixing in the code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.3 (including) 6.6.100 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.7 (including) 6.12.40 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.15.8 (excluding)
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*