
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38412 is a NULL pointer dereference / improper validation vulnerability in the Linux kernel's platform/x86: dell-wmi-sysman driver that allows a low-privileged local attacker to trigger a denial of service. The flaw was published on July 25, 2025, and affects Linux kernel versions from 5.11 up to (but not including) 5.15.187, 5.16 through 6.1.143, 6.2 through 6.6.96, 6.7 through 6.12.36, and 6.13 through 6.15.5, as well as release candidates 6.16-rc1 through 6.16-rc4. Debian Linux 11.0 is also listed as an affected product. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly).
The root cause is insufficient validation of WMI (Windows Management Instrumentation) data blocks retrieved during sysfs callbacks in the dell-wmi-sysman kernel driver (CWE-476: NULL Pointer Dereference). Specifically, after calling the WMI data block retrieval function, the driver failed to check whether the returned pointer was valid before dereferencing it, creating a condition where a NULL or invalid pointer dereference could occur. An attacker with low-privilege local access could interact with the affected sysfs interface to trigger this code path and cause a kernel panic or system crash. The fix, applied across multiple stable kernel branches, adds validity checks on the retrieved WMI data block before any content is accessed (Feedly, Kernel Patch).
Successful exploitation results in a high-severity denial of service — a kernel panic or system crash — on the affected host. There is no confidentiality or integrity impact, as the vulnerability only affects availability. The scope is limited to the local system; lateral movement is not directly facilitated by this vulnerability, though a system crash could disrupt services and create secondary availability risks (Feedly).
There is no public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2025-38412 as of the time of writing. The EPSS score is approximately 0.024% (0.000240), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with low privileges, limiting the attack surface to authenticated users on affected Dell systems running vulnerable kernel versions (Feedly).
The Linux kernel maintainers have released patches across all affected stable branches. Users should update to the following fixed versions or later: 5.15.187, 6.1.144, 6.6.97, 6.12.37, 6.15.6, or 6.16-rc5. Ubuntu has issued security notices (USN-7774-1/2/5, USN-7775-1/2, USN-7776-1, USN-7833-1/2/3/4) covering various kernel flavors including FIPS, Azure, Oracle, GCP, and Nvidia Tegra IGX variants. As a temporary workaround where patching is not immediately possible, restricting low-privilege user access to the relevant sysfs interfaces or unloading the dell-wmi-sysman kernel module can reduce exposure (Feedly, Ubuntu USN-7774-1).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."