CVE-2025-38656: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start() Preserve the error code if iwl_setup_deferred_work() fails. The current code returns ERR_PTR(0) (which is NULL) on this path. I believe the missing error code potentially leads to a use after free involving debugfs.
Affected products
- Linux Linux Kernel: from 5.4.297, before 5.5 (fixed in 5.5); from 5.10.241, before 5.11 (fixed in 5.11); from 5.15.190, before 5.16 (fixed in 5.16); from 6.1.148, before 6.2 (fixed in 6.2); from 6.6.102, before 6.7 (fixed in 6.7); from 6.12.42, before 6.13 (fixed in 6.13)
Published 2025-08-22. Last modified 2026-07-30.