CVE-2025-38533

HIGH

Linux Kernel 6.3-6.6.99, 6.7-6.12.39, 6.13-6.15.7 - Out-of-bounds Write in Rx Buffer DMA Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: libwx: fix the using of Rx buffer DMA The wx_rx_buffer structure contained two DMA address fields: 'dma' and 'page_dma'. However, only 'page_dma' was actually initialized and used to program the Rx descriptor. But 'dma' was uninitialized and used in some paths. This could lead to undefined behavior, including DMA errors or use-after-free, if the uninitialized 'dma' was used. Althrough such error has not yet occurred, it is worth fixing in the code.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (15)
linux/Kernel 6.13.0 - 6.15.8linux
linux/Kernel 6.3.0 - 6.6.100linux
linux/Kernel 6.7.0 - 6.12.40linux
Linux/Linux < 6.3
Linux/Linux 3c47e8ae113a68da47987750d9896e325d0aeedd - 027701180a7bcb64c42eab291133ef0c87b5b6c5
Linux/Linux 3c47e8ae113a68da47987750d9896e325d0aeedd - 05c37b574997892a40a0e9b9b88a481566b2367d
Linux/Linux 3c47e8ae113a68da47987750d9896e325d0aeedd - 5fd77cc6bd9b368431a815a780e407b7781bcca0
Linux/Linux 3c47e8ae113a68da47987750d9896e325d0aeedd - ba7c793f96c1c2b944bb6f423d7243f3afc30fe9
Linux/Linux 6.12.40 - 6.12.*
Linux/Linux 6.15.8 - 6.15.*
... and 5 more
Published Aug 16, 2025
Tracked Since Feb 18, 2026