CVE-2025-40189 — Linux vulnerability
15 documents6 sources
Severity
—N/A
No vectorEPSS
0.0%
top 94.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
net: usb: lan78xx: Fix lost EEPROM read timeout error(-ETIMEDOUT) in lan78xx_read_raw_eeprom
Syzbot reported read of uninitialized variable BUG with following call stack.
lan78xx 8-1:1.0 (unnamed net_device) (uninitialized): EEPROM read operation timeout
BUG: KMSAN: uninit-value in lan78xx_read_eeprom drivers/net/usb/lan78xx.c:1095 [inline]
BUG: KMSAN: uninit-value in lan78xx_init_mac_address drivers/net/usb/lan78xx.c:1937 [i…
Affected Packages5 packages
▶CVEListV5linux/linux8b1b2ca83b200fa46fdfb81e80ad5fe34537e6d4 — a72a7c4f675080a324d4c2167bd2314d968279f1+2
🔴Vulnerability Details
8📋Vendor Advisories
6Red Hat▶
kernel: net: usb: lan78xx: Fix lost EEPROM read timeout error(-ETIMEDOUT) in lan78xx_read_raw_eeprom↗2025-11-12