In the Linux kernel, the following vulnerability has been resolved:
net: usb: asix_devices: Fix PHY address mask in MDIO bus initialization
Syzbot reported shift-out-of-bounds exception on MDIO bus initialization.
The PHY address should be masked to 5 bits (0-31). Without this mask, invalid PHY addresses could be used, potentially causing issues with MDIO bus operations.
Fix this by masking the PHY address with 0x1f (31 decimal) to ensure it stays within the valid range.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@748da80831221ae24b4bc8d7ffb22acd5712a341",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-327386f7",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"151908035299312305856544629376846927191"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@24ef2f53c07f273bad99173e27ee88d44d135b1c",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-33298847",
"digest": {
"function_hash": "240242981234012784902214491873261355342",
"length": 730.0
},
"signature_type": "Function",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f141f2a4f2ef8ca865d5921574c3d6535e00a49",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-398a28ed",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"151908035299312305856544629376846927191"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@523eab02fce458fa6d3c51de5bb055800986953e",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-47edcfdf",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"151908035299312305856544629376846927191"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@748da80831221ae24b4bc8d7ffb22acd5712a341",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-527f96cb",
"digest": {
"function_hash": "240242981234012784902214491873261355342",
"length": 730.0
},
"signature_type": "Function",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22042ffedd8c2c6db08ccdd6d4273068eddd3c5c",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-5742ea94",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"151908035299312305856544629376846927191"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@523eab02fce458fa6d3c51de5bb055800986953e",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-5fef2649",
"digest": {
"function_hash": "240242981234012784902214491873261355342",
"length": 730.0
},
"signature_type": "Function",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@24ef2f53c07f273bad99173e27ee88d44d135b1c",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-b3b3b0a3",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"151908035299312305856544629376846927191"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fcb4ce9f729c1d08e53abf9d449340e24c3edee6",
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"id": "CVE-2025-38736-bebb4a2e",
"digest": {
"threshold": 0.9,
"line_hashes": [
"61858926264902438027659094136113946688",
"10040837167315576258241079053515718621",
"201174127018602760346499589256009899505",
"158274626271589681186484155767824860474"
]
},
"signature_type": "Line",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8f141f2a4f2ef8ca865d5921574c3d6535e00a49",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-cb898535",
"digest": {
"function_hash": "240242981234012784902214491873261355342",
"length": 730.0
},
"signature_type": "Function",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@22042ffedd8c2c6db08ccdd6d4273068eddd3c5c",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-ce690d60",
"digest": {
"function_hash": "240242981234012784902214491873261355342",
"length": 730.0
},
"signature_type": "Function",
"deprecated": false
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@fcb4ce9f729c1d08e53abf9d449340e24c3edee6",
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"id": "CVE-2025-38736-dac553f4",
"digest": {
"function_hash": "12094204122846428093299939035474735858",
"length": 618.0
},
"signature_type": "Function",
"deprecated": false
}
]