CVE-2025-38412
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38412 is a vulnerability discovered in the Linux kernel's dell-wmi-sysman driver, specifically affecting the WMI data block retrieval in sysfs callbacks. The vulnerability was disclosed on July 25, 2025, and primarily affects the platform/x86 component (NVD, Red Hat).

Technical details

The vulnerability stems from insufficient validation of ACPI package structures retrieved through WMI sysfs callbacks in the dell-wmi-sysman driver. The issue occurs after retrieving WMI data blocks in sysfs callbacks, where the code fails to properly check the validity of the data before dereferencing their content. The vulnerability has been assigned a CVSS v3.1 base score of 6.1 with a vector string of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H and is associated with CWE-129 (Red Hat).

Impact

The vulnerability can lead to kernel crashes or potential memory leaks when exploited. A local user with sysfs access can trigger these conditions by crafting malformed ACPI responses or through race condition exploitation (Red Hat).

Mitigation and workarounds

As a temporary mitigation, system administrators can prevent the dell-wmi-sysman module from being loaded. Red Hat provides guidance on blacklisting kernel modules to prevent automatic loading. For permanent remediation, users should apply the latest kernel updates when available (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel-matched
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • linux-gcp
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-modules-extra
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management