CVE-2025-71094

Description

An input validation vulnerability was found in the Linux kernel's ASIX USB Ethernet driver. The driver reads the PHY address from the USB device without validating that it falls within the valid range (0 to PHY_MAX_ADDR-1). A malicious or faulty USB device can provide an invalid PHY address, causing a kernel warning when mdiobus_get_phy() attempts to use the out-of-range address.

Statement

This vulnerability requires physical access to connect a malicious USB device. The impact is limited to a kernel warning message; the invalid address is rejected before it can cause further damage. While the warning indicates a potential issue, it does not result in a crash or security compromise.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score45.5N/A
Attack VectorPhysicalLocalN/A
Attack ComplexityHighLowN/A
Privileges RequiredLowLowN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityNoneNoneN/A
Integrity ImpactNoneNoneN/A
Availability ImpactHighHighN/A

Vector

Red Hat: CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

NVD: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.