CVE-2025-38644
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38644 is a use of uninitialized resource vulnerability in the Linux kernel's mac80211 wireless subsystem, specifically in the ieee80211_tdls_oper() function. It affects Linux kernel versions from 3.17 through multiple stable branches, with fixed versions at 6.1.148, 6.6.102, 6.12.42, 6.15.10, and 6.16.1. Debian Linux 11.0 is also listed as an affected platform. The vulnerability was published on August 22, 2025, and carries a CVSS v3.1 base score of 5.5 (Medium) (Red Hat Advisory, Feedly).

Technical details

The root cause is classified as CWE-908 (Use of Uninitialized Resource). The vulnerability was discovered via syzbot fuzzing, which triggered a WARN_ON() in ieee80211_tdls_oper() by sending NL80211_TDLS_ENABLE_LINK immediately after NL80211_CMD_CONNECT, before association with an access point completed and without prior TDLS setup. This race condition leaves internal state — specifically sdata->u.mgd.tdls_peer — uninitialized, causing code paths that assume it is valid to trigger kernel warnings. The fix adds an early rejection of TDLS operations when the interface is not in station mode or not yet associated (Feedly, Red Hat Advisory).

Impact

A local attacker with low privileges can trigger kernel WARN_ON() assertions, potentially causing the kernel to become unstable or crash, resulting in a denial of service. The vulnerability has no impact on confidentiality or integrity — only system availability is affected. Systems running affected kernel versions with wireless interfaces in station mode are at risk, and the impact is limited to the local machine with no lateral movement potential (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (Feedly). The vulnerability requires local access with low privileges and the ability to send netlink wireless configuration commands. The EPSS score is approximately 0.024% (0.000240), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

Upgrade to a patched Linux kernel version: 6.1.148 or later (for the 6.1.x branch), 6.6.102 or later (for 6.2–6.6.x), 6.12.42 or later (for 6.7–6.12.x), 6.15.10 or later (for 6.13–6.15.x), or 6.16.1 or later (for 6.16.x). Distributions including SUSE, openSUSE, Oracle Linux, and Debian have released updated kernel packages addressing this issue. As a workaround, restricting access to netlink wireless configuration interfaces (e.g., via capability controls or namespace isolation) to trusted users can reduce exposure (Red Hat Advisory, Feedly).

Community reactions

Red Hat published a security advisory tracking this CVE, and multiple Linux distribution vendors — including SUSE, openSUSE, and Oracle Linux — have issued kernel update advisories addressing this vulnerability. Coverage has been largely routine, consistent with standard Linux kernel patch releases, with no notable researcher commentary or significant social media discussion observed (Red Hat Advisory, Linux Security SUSE).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-68450NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-core
NoYesAug 12, 2026
CVE-2026-68449NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-debug-devel
NoYesAug 12, 2026
CVE-2026-68448NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-modules-extra
NoYesAug 12, 2026
CVE-2026-68447NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel-rt-modules
NoYesAug 12, 2026
CVE-2026-68446NONEN/A
  • Linux Kernel logoLinux Kernel
  • kernel.src
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management