CVE-2025-38096
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38096 is a Denial of Service vulnerability in the Linux kernel's iwlwifi wireless driver caused by improper firmware error handling. Specifically, the iwl_trans_reclaim function emits an unnecessary warning when called while the firmware is not alive — including during a pending firmware restart following a firmware error — instead of returning silently. The vulnerability affects Linux kernel versions prior to 6.12.31 and versions 6.13.x prior to 6.14.9. It was published on July 3, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper handling of firmware error states within the iwl_trans_reclaim function in the iwlwifi driver (CWE-703: Improper Check or Handling of Exceptional Conditions). When a firmware error triggers a pending restart, the function incorrectly raises a kernel warning rather than silently returning, which can disrupt normal driver operation. The attack vector is local, requiring low privileges, and no user interaction is needed. The fix modifies the function to detect the pending-restart condition and return silently instead of warning (Red Hat Bugzilla, Kernel Patch).

Impact

Successful exploitation of this vulnerability can result in a Denial of Service condition affecting the availability of the wireless networking subsystem on systems using Intel Wi-Fi (iwlwifi) hardware. There is no impact on confidentiality or integrity. The scope is limited to the local system, and there is no known potential for lateral movement or data exfiltration (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).

Mitigation and workarounds

Patches are available in Linux kernel versions 6.12.31, 6.14.9, and 6.15. Users should update to one of these patched versions as the primary remediation. Distributions including Ubuntu and SUSE have issued updated kernel packages addressing this vulnerability (Ubuntu USN-7770-1, USN-7789-1, USN-7789-2; SUSE advisories SUSE-2025-20994-1, SUSE-2025-21074-1, SUSE-2025-21139-1). As a secondary measure, systems without Intel Wi-Fi hardware or that do not use the iwlwifi driver are not affected (Red Hat Advisory, Kernel Patch).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68454HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-aws-6.17
NoYesAug 13, 2026
CVE-2026-68452HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-modules-core
NoYesAug 13, 2026
CVE-2026-68451HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-rt-64k-modules-partner
NoYesAug 13, 2026
CVE-2026-68453HIGH7.1
  • Linux Kernel logoLinux Kernel
  • kernel-64k-modules-extra
NoYesAug 13, 2026
CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-core
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management