cbcvebase.
CVE-2025-38422
published 2025-07-25

CVE-2025-38422: In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on device. Also prevent out-of-bound read/write.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux>= 695846047aa9b4bb387473a9fd227a51ae7de5e9 < 6b4201d74d0a49af2123abf2c9d142e59566714b6b4201d74d0a49af2123abf2c9d142e59566714b
linuxlinux>= 695846047aa9b4bb387473a9fd227a51ae7de5e9 < 088279ff18cdc437d6fac5890e0c52c624f78a5b088279ff18cdc437d6fac5890e0c52c624f78a5b
linuxlinux>= 695846047aa9b4bb387473a9fd227a51ae7de5e9 < 51318d644c993b3f7a60b8616a6a5adc1e967cd251318d644c993b3f7a60b8616a6a5adc1e967cd2
linuxlinux>= 695846047aa9b4bb387473a9fd227a51ae7de5e9 < 9c41d2a2aa3817946eb613522200cab55513ddaa9c41d2a2aa3817946eb613522200cab55513ddaa
linuxlinux>= 695846047aa9b4bb387473a9fd227a51ae7de5e9 < 3b9935586a9b54d2da27901b830d3cf46ad66a1e3b9935586a9b54d2da27901b830d3cf46ad66a1e
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.12.35-16.12.35-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 4.19 < 6.1.1426.1.142
linuxlinux_kernel>= 6.13 < 6.15.46.15.4
linuxlinux_kernel>= 6.2 < 6.6.956.6.95
linuxlinux_kernel>= 6.7 < 6.12.356.12.35
msrcazl3_kernel_6.6.92.2-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.186.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
msrccbl2_kernel_5.15.202.1-1_on_cbl_mariner_2.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH