Junglewise Threat Intelligence

CVE-2025-38725: Linux Kernel NULL pointer dereference in ASIX USB MDIO bus

CVE-2025-38725 · Severity: medium · CVSS 5.5 · Published 2025-09-04

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's ASIX USB network driver can cause a system crash (Blue Screen equivalent) when certain USB Ethernet adapters are used. The issue occurs when the system attempts to enter or wake up from sleep mode (suspend/resume). This primarily affects industrial and networking hardware using the AX88772 chipset, potentially leading to unexpected downtime or service interruptions.

Technical details

A NULL pointer dereference exists in the Linux kernel's asix_devices.c driver for AX88772-based USB MDIO buses. The vulnerability is triggered because the driver fails to set a 'phy_mask', causing it to incorrectly create up to 32 MDIO PHY devices. During system suspend or resume cycles, the 'phy_state_machine()' calls 'phy_polling_mode()', which attempts to dereference members of 'phydev->drv' for these secondary, unbound PHY devices. Since only the primary PHY is bound to a driver, the 'drv' member is NULL for others, resulting in a kernel panic. The fix involves implementing a proper 'phy_mask' to restrict device creation to only the necessary internal or external PHY.

Affected products

  • Linux Linux Kernel e532a096be0e to 4faff70959d5
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-08-11: patched: Initial patch authored by Xu Yang
  • 2025-09-04: disclosed: CVE published

References

Related threats