cbcvebase.
CVE-2025-71196
published 2026-02-04

CVE-2025-71196: In the Linux kernel, the following vulnerability has been resolved: phy: stm32-usphyc: Fix off by one in probe() The "index" variable is used as an index into…

PriorityP422high7.8
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: phy: stm32-usphyc: Fix off by one in probe() The "index" variable is used as an index into the usbphyc->phys[] array which has usbphyc->nphys elements. So if it is equal to usbphyc->nphys then it is one element out of bounds. The "index" comes from the device tree so it's data that we trust and it's unlikely to be wrong, however it's obviously still worth fixing the bug. Change the > to >=.

Affected

61 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < a9eec890879731c280697fdf1c50699e905b2fa7a9eec890879731c280697fdf1c50699e905b2fa7
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < fb9d513cdf1614bf0f0e785816afb1faae3f81affb9d513cdf1614bf0f0e785816afb1faae3f81af
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < c06f13876cbad702582cd67fc77356e5524d02cdc06f13876cbad702582cd67fc77356e5524d02cd
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < 76b870fdaad82171a24b8aacffe5e4d9e0d2ee2c76b870fdaad82171a24b8aacffe5e4d9e0d2ee2c
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < b91c9f6bfb04e430adeeac7e7ebc9d80f9d72badb91c9f6bfb04e430adeeac7e7ebc9d80f9d72bad
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < 7c27eaf183563b86d815ff6e9cca0210b4cfa0517c27eaf183563b86d815ff6e9cca0210b4cfa051
linuxlinux>= 94c358da3a0545205c6c6a50ae26141f1c73acfa < cabd25b57216ddc132efbcc31f972baa03aad15acabd25b57216ddc132efbcc31f972baa03aad15a
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.69-16.12.69-1
linuxlinux_kernel>= 0 < 6.18.8-16.18.8-1
linuxlinux_kernel>= 4.17.0 < 5.10.2495.10.249
linuxlinux_kernel>= 5.11.0 < 5.15.1995.15.199
linuxlinux_kernel>= 5.16.0 < 6.1.1626.1.162
linuxlinux_kernel>= 6.13.0 < 6.18.76.18.7
linuxlinux_kernel>= 6.2.0 < 6.6.1226.6.122
linuxlinux_kernel>= 6.7.0 < 6.12.676.12.67
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.