cbcvebase.
CVE-2025-38725
published 2025-09-04

CVE-2025-38725: In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
debianlinux-6.1< linux 6.1.153-1 (bookworm)linux 6.1.153-1 (bookworm)
linuxlinux
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < 75947d3200de98a9ded9ad8972e02f1a177097fe75947d3200de98a9ded9ad8972e02f1a177097fe
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < 59ed6fbdb1bc03316e09493ffde7066f031c752459ed6fbdb1bc03316e09493ffde7066f031c7524
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < ccef5ee4adf56472aa26bdd1f821a6d0cd06089accef5ee4adf56472aa26bdd1f821a6d0cd06089a
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < ee2cd40b0bb46056949a2319084a729d95389386ee2cd40b0bb46056949a2319084a729d95389386
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < a754ab53993b1585132e871c5d811167ad3c52ffa754ab53993b1585132e871c5d811167ad3c52ff
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < ad1f8313aeec0115f9978bd2d002ef4a8d96c773ad1f8313aeec0115f9978bd2d002ef4a8d96c773
linuxlinux>= e532a096be0e5e570b383e71d4560e7f04384e0f < 4faff70959d51078f9ee8372f8cff0d7045e41144faff70959d51078f9ee8372f8cff0d7045e4114
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.153-16.1.153-1
linuxlinux_kernel>= 0 < 6.12.43-16.12.43-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 5.15.0-163.1735.15.0-163.173
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.14 < 5.15.1905.15.190
linuxlinux_kernel>= 5.16 < 6.1.1496.1.149
linuxlinux_kernel>= 6.13 < 6.15.116.15.11
linuxlinux_kernel>= 6.16 < 6.16.26.16.2
linuxlinux_kernel>= 6.2 < 6.6.1036.6.103
linuxlinux_kernel>= 6.7 < 6.12.436.12.43
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM