CVE-2025-38661 (GCVE-0-2025-38661)

Vulnerability from cvelistv5 – Published: 2025-08-22 16:02 – Updated: 2026-08-05 12:03
VLAI
Title
platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array
Summary
In the Linux kernel, the following vulnerability has been resolved: platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array Add missing empty member to `awcc_dmi_table`.
Impacted products
Vendor Product Version
Linux Linux Affected: 6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f , < 660bcd9f1f94e623e1316b869b2172b36eb516d7 (git)
Affected: 6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f , < 8346c6af27f1c1410eb314f4be5875fdf1579a10 (git)
Create a notification for this product.
Linux Linux Affected: 6.15
Unaffected: 0 , < 6.15 (semver)
Unaffected: 6.15.9 , ≤ 6.15.* (semver)
Unaffected: 6.16 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/dell/alienware-wmi-wmax.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "660bcd9f1f94e623e1316b869b2172b36eb516d7",
              "status": "affected",
              "version": "6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f",
              "versionType": "git"
            },
            {
              "lessThan": "8346c6af27f1c1410eb314f4be5875fdf1579a10",
              "status": "affected",
              "version": "6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/platform/x86/dell/alienware-wmi-wmax.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.15"
            },
            {
              "lessThan": "6.15",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.15.*",
              "status": "unaffected",
              "version": "6.15.9",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.16",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15.9",
                  "versionStartIncluding": "6.15",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.16",
                  "versionStartIncluding": "6.15",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array\n\nAdd missing empty member to `awcc_dmi_table`."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The defect is in `__init` code of a locally-loaded platform driver reached only through module load/boot on the affected hardware; there is no network, adjacent, or remote-peer input path into `dmi_first_match(awcc_dmi_table)`. Local access is the highest defensible vector since module loading and module-parameter control are local operations.\nAC:L - The out-of-bounds walk happens deterministically every time `alienware_wmax_wmi_init()` runs on a machine exposing WMAX_CONTROL_GUID \u2014 no race to win, no memory-layout grooming, and the driver config is default-enabled in distro kernels. Nothing about triggering it depends on conditions outside the attacker\u0027s reach.\nPR:L - The over-read executes as part of normal module initialization on affected systems, so it occurs without any privileged action, and consistent with prior kernel CNA scoring of missing-terminator OOB reads (CVE-2025-68195) no elevated privilege is credited. Low is chosen over High per the higher-severity-when-uncertain rule.\nUI:N - The table walk runs automatically during driver init at boot via udev autoload; no victim must open a file, mount anything, or take any other action.\nS:U - The out-of-bounds access and any resulting corruption stay entirely within the kernel\u0027s own security authority \u2014 no hypervisor, IOMMU, or sandbox boundary is crossed.\nC:H - The read is unbounded rather than a few stray bytes: it walks arbitrarily far past the array in `.init.rodata` and, via a 7-bit `slot` value up to 127 indexing the 23-element `dmi_ident[]`, pulls a value from adjacent kernel static data and dereferences it as a string pointer, exposing arbitrary kernel memory to the matching logic.\nI:N - No attacker-controlled write primitive exists \u2014 the only writes through the garbage `awcc` pointer are fixed `true` bytes gated behind root-only, non-default `module_param_unsafe` force_* parameters, to an address the attacker cannot steer.\nA:H - Dereferencing an out-of-bounds `dmi_ident[]` entry as a string pointer, and later dereferencing the bogus `driver_data` value cached in the global `awcc`, readily oopses the kernel during boot-time driver initialization; KASAN builds report the out-of-bounds access outright."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:03:48.256Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/660bcd9f1f94e623e1316b869b2172b36eb516d7"
        },
        {
          "url": "https://git.kernel.org/stable/c/8346c6af27f1c1410eb314f4be5875fdf1579a10"
        }
      ],
      "title": "platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-38661",
    "datePublished": "2025-08-22T16:02:54.362Z",
    "dateReserved": "2025-04-16T04:51:24.031Z",
    "dateUpdated": "2026-08-05T12:03:48.256Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2025-38661",
      "date": "2026-10-03",
      "epss": "0.00143",
      "percentile": "0.03095"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "drivers/platform/x86/dell/alienware-wmi-wmax.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "660bcd9f1f94e623e1316b869b2172b36eb516d7",
                    "status": "affected",
                    "version": "6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "8346c6af27f1c1410eb314f4be5875fdf1579a10",
                    "status": "affected",
                    "version": "6d7f1b1a5db61c4d654c84e17392916c4ef8ae6f",
                    "versionType": "git"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "drivers/platform/x86/dell/alienware-wmi-wmax.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "6.15"
                  },
                  {
                    "lessThan": "6.15",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.15.*",
                    "status": "unaffected",
                    "version": "6.15.9",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "6.16",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "configurations": [
          {
            "nodes": [
              {
                "cpeMatch": [
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                    "matchCriteriaId": "1D8E7F85-B85D-4D13-8A40-7127AF8B86B0",
                    "versionEndExcluding": "6.15.9",
                    "versionStartIncluding": "6.15",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*",
                    "matchCriteriaId": "6D4894DB-CCFE-4602-B1BF-3960B2E19A01",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*",
                    "matchCriteriaId": "09709862-E348-4378-8632-5A7813EDDC86",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*",
                    "matchCriteriaId": "415BF58A-8197-43F5-B3D7-D1D63057A26E",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*",
                    "matchCriteriaId": "A0517869-312D-4429-80C2-561086E1421C",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*",
                    "matchCriteriaId": "85421F4E-C863-4ABF-B4B4-E887CC2F7F92",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*",
                    "matchCriteriaId": "3827F0D4-5FEE-4181-B267-5A45E7CA11FC",
                    "vulnerable": true
                  },
                  {
                    "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc7:*:*:*:*:*:*",
                    "matchCriteriaId": "7A9C2DE5-43B8-4D73-BDB5-EA55C7671A52",
                    "vulnerable": true
                  }
                ],
                "negate": false,
                "operator": "OR"
              }
            ]
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nplatform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array\n\nAdd missing empty member to `awcc_dmi_table`."
          },
          {
            "lang": "es",
            "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: plataforma/x86: alienware-wmi-wmax: Se corrige la matriz `dmi_system_id`. Se agrega un miembro vac\u00edo faltante a `awcc_dmi_table`."
          }
        ],
        "id": "CVE-2025-38661",
        "lastModified": "2026-07-30T06:23:33.790",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.2,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            },
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 5.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 3.6,
              "source": "nvd@nist.gov",
              "type": "Primary"
            }
          ]
        },
        "published": "2025-08-22T16:15:41.330",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/660bcd9f1f94e623e1316b869b2172b36eb516d7"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "tags": [
              "Patch"
            ],
            "url": "https://git.kernel.org/stable/c/8346c6af27f1c1410eb314f4be5875fdf1579a10"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Modified",
        "weaknesses": [
          {
            "description": [
              {
                "lang": "en",
                "value": "NVD-CWE-noinfo"
              }
            ],
            "source": "nvd@nist.gov",
            "type": "Primary"
          }
        ]
      }
    },
    "redhat_vex": {
      "aggregate_severity": "None",
      "current_release_date": "2026-06-30T10:26:25+00:00",
      "cve": "CVE-2025-38661",
      "id": "CVE-2025-38661",
      "initial_release_date": "2025-08-22T00:00:00+00:00",
      "product_status:known_not_affected": "274",
      "source": "Red Hat CSAF VEX",
      "status": "final",
      "title": "kernel: platform/x86: alienware-wmi-wmax: Fix `dmi_system_id` array",
      "url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-38661.json",
      "version": "3"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…