In the Linux kernel, the following vulnerability has been resolved:
usb: net: sierra: check for no status endpoint
The driver checks for having three endpoints and having bulk in and out endpoints, but not that the third endpoint is interrupt input. Rectify the omission.
[
{
"id": "CVE-2025-38474-09d95004",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5dd6a441748dad2f02e27b256984ca0b2d4546b6",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-0f27b239",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bfe8ef373986e8f185d3d6613eb1801a8749837a",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
},
{
"id": "CVE-2025-38474-16f7bbe2",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5408cc668e596c81cdd29e137225432aa40d1785",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-1b3bc867",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c4ca3c46167518f8534ed70f6e3b4bf86c4d158",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
},
{
"id": "CVE-2025-38474-1fd59ad3",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bfe8ef373986e8f185d3d6613eb1801a8749837a",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-215d9d47",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c4ca3c46167518f8534ed70f6e3b4bf86c4d158",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-2d730ffa",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5849980faea1c792d1d5e54fdbf1e69ac0a9bfb9",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-300fae7b",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5dd6a441748dad2f02e27b256984ca0b2d4546b6",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
},
{
"id": "CVE-2025-38474-629e1175",
"target": {
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Line",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6a238c4126eb3ddb495d3f960193ca5bb778d92",
"digest": {
"line_hashes": [
"138347129656644471509123291692873571763",
"332066084183336805000611386149014412217",
"287502190653591107104466373730298097919",
"269563831859344612767795958061471021090"
],
"threshold": 0.9
}
},
{
"id": "CVE-2025-38474-6bb6845a",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a6a238c4126eb3ddb495d3f960193ca5bb778d92",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
},
{
"id": "CVE-2025-38474-c6cf576c",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5849980faea1c792d1d5e54fdbf1e69ac0a9bfb9",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
},
{
"id": "CVE-2025-38474-fc7b87de",
"target": {
"function": "sierra_net_bind",
"file": "drivers/net/usb/sierra_net.c"
},
"signature_version": "v1",
"signature_type": "Function",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5408cc668e596c81cdd29e137225432aa40d1785",
"digest": {
"length": 2259.0,
"function_hash": "328062028874004260605560259765241652612"
}
}
]