Junglewise Threat Intelligence

CVE-2025-38533: Linux Kernel libwx uninitialized DMA address in Rx buffer

CVE-2025-38533 · Severity: critical · CVSS 9.8 · Published 2025-08-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Wangxun (libwx) network driver, which manages how the computer's network hardware communicates with system memory. Due to a coding error, the system could attempt to access memory using uninitialized addresses, potentially leading to system crashes or unauthorized data access. This could impact the stability and security of servers or workstations using this specific networking hardware.

Technical details

A vulnerability in the libwx driver (drivers/net/ethernet/wangxun/libwx) stems from the 'wx_rx_buffer' structure containing two DMA address fields: 'dma' and 'page_dma'. While 'page_dma' was correctly initialized, the 'dma' field remained uninitialized yet was utilized in certain code paths, such as Rx descriptor programming. This mismatch can result in DMA errors, use-after-free conditions, or out-of-bounds writes (CWE-787). Although the kernel maintainers note no known exploits, the flaw is reachable via network traffic processed by the affected driver. Patches have been released for multiple stable kernel branches including 6.6.y, 6.12.y, and 6.15.y.

Affected products

  • Linux Linux Kernel 6.3 to 6.6.100, 6.7 to 6.12.40, 6.13 to 6.15.8

Timeline

  • 2025-07-14: patched: Initial patch submitted by Jiawen Wu
  • 2025-08-16: disclosed: CVE-2025-38533 published

References

Related threats