Junglewise Threat Intelligence

CVE-2025-38111: Linux Kernel out-of-bounds access in net/mdiobus

CVE-2025-38111 · Severity: high · CVSS 7.1 · Published 2025-07-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to perform unauthorized memory operations. The issue exists in how the system handles communication with network hardware (PHY) via the MDIO bus. An attacker with local access could potentially read sensitive information or cause a system crash, impacting the stability and confidentiality of the affected machine.

Technical details

An out-of-bounds (OOB) read/write vulnerability exists in the Linux kernel's net/mdiobus component. The root cause is a lack of bounds checking on the MDIO address parameter passed via ioctl calls. While the kernel defines a maximum of 32 addresses (PHY_MAX_ADDR), the ioctl interface accepted higher values without verification. When these invalid addresses are used, the kernel may attempt to access the mdiobus statistics array out-of-bounds. A local attacker with low privileges can trigger this behavior using tools like 'mdio-tools' to interact with network interfaces. This can result in the disclosure of kernel memory or a system crash. The vulnerability has been addressed by adding explicit address verification in the __mdiobus_read and __mdiobus_write functions.

Affected products

  • Linux Linux Kernel 5.6 to 5.10.239, 5.11 to 5.15.186, 5.16 to 6.1.142, 6.2 to 6.6.94, 6.7 to 6.12.34, 6.13 to 6.15.3, 6.16-rc1

Timeline

  • 2025-06-09: other: Patch authored
  • 2025-07-03: disclosed: Vulnerability published
  • 2025-12-16: other: NVD analysis completed

References

Related threats