
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38096 is a Denial of Service vulnerability in the Linux kernel's iwlwifi wireless driver caused by improper firmware error handling. Specifically, the iwl_trans_reclaim function emits an unnecessary warning when called while the firmware is not alive — including during a pending firmware restart following a firmware error — instead of returning silently. The vulnerability affects Linux kernel versions prior to 6.12.31 and versions 6.13.x prior to 6.14.9. It was published on July 3, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is improper handling of firmware error states within the iwl_trans_reclaim function in the iwlwifi driver (CWE-703: Improper Check or Handling of Exceptional Conditions). When a firmware error triggers a pending restart, the function incorrectly raises a kernel warning rather than silently returning, which can disrupt normal driver operation. The attack vector is local, requiring low privileges, and no user interaction is needed. The fix modifies the function to detect the pending-restart condition and return silently instead of warning (Red Hat Bugzilla, Kernel Patch).
Successful exploitation of this vulnerability can result in a Denial of Service condition affecting the availability of the wireless networking subsystem on systems using Intel Wi-Fi (iwlwifi) hardware. There is no impact on confidentiality or integrity. The scope is limited to the local system, and there is no known potential for lateral movement or data exfiltration (Red Hat Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory).
Patches are available in Linux kernel versions 6.12.31, 6.14.9, and 6.15. Users should update to one of these patched versions as the primary remediation. Distributions including Ubuntu and SUSE have issued updated kernel packages addressing this vulnerability (Ubuntu USN-7770-1, USN-7789-1, USN-7789-2; SUSE advisories SUSE-2025-20994-1, SUSE-2025-21074-1, SUSE-2025-21139-1). As a secondary measure, systems without Intel Wi-Fi hardware or that do not use the iwlwifi driver are not affected (Red Hat Advisory, Kernel Patch).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."