cbcvebase.
CVE-2025-71094
published 2026-01-13

CVE-2025-71094: In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use The ASIX driver reads the PHY address from…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use The ASIX driver reads the PHY address from the USB device via asix_read_phy_addr(). A malicious or faulty device can return an invalid address (>= PHY_MAX_ADDR), which causes a warning in mdiobus_get_phy(): addr 207 out of range WARNING: drivers/net/phy/mdio_bus.c:76 Validate the PHY address in asix_read_phy_addr() and remove the now-redundant check in ax88172a.c.

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.13.13 < 5.145.14
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < fc96018f09f8d30586ca6582c5045a84eafef146fc96018f09f8d30586ca6582c5045a84eafef146
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < f5f4f30f3811d37e1aa48667c36add74e5a8d99ff5f4f30f3811d37e1aa48667c36add74e5a8d99f
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < 38722e69ee64dbb020028c93898d25d6f4c0e0b238722e69ee64dbb020028c93898d25d6f4c0e0b2
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < 98a12c2547a44a5f03f35c108d2022cc652cbc4d98a12c2547a44a5f03f35c108d2022cc652cbc4d
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < bf8a0f3b787ca7c5889bfca12c60c483041fbee3bf8a0f3b787ca7c5889bfca12c60c483041fbee3
linuxlinux>= 7e88b11a862afe59ee0c365123ea5fb96a26cb3b < a1e077a3f76eea0dc671ed6792e7d543946227e8a1e077a3f76eea0dc671ed6792e7d543946227e8
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.5-16.18.5-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 5.13.13 < 5.145.14
linuxlinux_kernel>= 5.14.0 < 5.15.1985.15.198
linuxlinux_kernel>= 5.14.1 < 5.15.1985.15.198
linuxlinux_kernel>= 5.16 < 6.1.1606.1.160
linuxlinux_kernel>= 5.16.0 < 6.1.1606.1.160
linuxlinux_kernel>= 6.13 < 6.18.46.18.4
linuxlinux_kernel>= 6.13.0 < 6.18.46.18.4
linuxlinux_kernel>= 6.2 < 6.6.1206.6.120

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.