CVE-2025-38412

MEDIUM

Linux Kernel 5.11-6.15.5 - DoS via Invalid WMI Data Block Dereference

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: platform/x86: dell-wmi-sysman: Fix WMI data block retrieval in sysfs callbacks After retrieving WMI data blocks in sysfs callbacks, check for the validity of them before dereferencing their content.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (22)
debian/debian_linux 11.0
linux/Kernel 5.11.0 - 5.15.187linux
linux/Kernel 5.16.0 - 6.1.144linux
linux/Kernel 6.13.0 - 6.15.6linux
linux/Kernel 6.2.0 - 6.6.97linux
linux/Kernel 6.7.0 - 6.12.37linux
Linux/Linux < 5.11
Linux/Linux 5.11
Linux/Linux 5.15.187 - 5.15.*
Linux/Linux 6.1.144 - 6.1.*
... and 12 more
Published Jul 25, 2025
Tracked Since Feb 18, 2026