VDB

DEBIAN-CVE-2025-38725

DEBIAN-CVE-2025-38725 PUBLISHED CVSS 5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: net: usb: asix_devices: add phy_mask for ax88772 mdio bus Without setting phy_mask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phy_polling_mode() in phy_state_machine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phy_mask for ax88772 mdio bus to workarnoud the issue.

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Debian:13linux6.12.41-1, 6.12.43-1, 6.12.41-1
Debian:11linux-6.16.1.112-1, 6.1.106-3, 6.1.106-3
Debian:14linux6.15.5-1~exp1, 6.15~rc7-1~exp1, 6.16-1~exp1
Debian:12linux6.1.90-1~bpo11+1, 6.1.94-1, 6.1.94-1~bpo11+1

Timeline

  • Sep 4, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›