CVE-2025-38156

MEDIUM EPSS 3.4%
Published Jul 3, 202512mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Jul 3, 2025 12mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Fix null-ptr-deref in mt7996_mmio_wed_init() devm_ioremap() returns NULL on error. Currently, mt7996_mmio_wed_init() does not check for this case, which results in a NULL pointer dereference. Prevent null pointer dereference in mt7996_mmio_wed_init()

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
3.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 2

VendorProductVersionRange
linuxlinux_kernel*≥6.8  –  <6.12.34
linuxlinux_kernel*≥6.13  –  <6.15.3

References 3

  • git.kernel.org https://git.kernel.org/stable/c/1072fc0ca1f8d0d5397d24853386876f937b8e63
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8f30e2b059757d8711a823e4c9c023db62a1d171
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/af861c6dea2ef06845a5c7672999a06c06099735
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/1072fc0ca1f8d0d5397d24853386876f937b8e63
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8f30e2b059757d8711a823e4c9c023db62a1d171
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/af861c6dea2ef06845a5c7672999a06c06099735
    Patch