Junglewise Threat Intelligence

CVE-2025-38736: Linux Kernel shift-out-of-bounds in ASIX USB network driver

CVE-2025-38736 · Severity: high · CVSS 7.1 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability was identified in the Linux kernel's driver for ASIX USB network devices, which are commonly used to provide Ethernet connectivity to computers and industrial equipment. An error in how the system handles internal hardware addresses could allow a local attacker to cause a system crash or potentially access restricted memory. This issue affects various Linux-based systems, including certain Siemens industrial controllers used in manufacturing and automation environments.

Technical details

A shift-out-of-bounds exception (CWE-125) exists in the Linux kernel in drivers/net/usb/asix_devices.c. The vulnerability occurs during MDIO bus initialization for AX88772 devices because the PHY address is not properly masked to its valid 5-bit range (0-31). When an invalid PHY address is processed, it leads to an out-of-bounds bitwise shift operation. A local attacker can trigger this flaw to cause a kernel panic (DoS) or potentially perform out-of-bounds reads. The issue has been resolved by applying a 0x1f mask to the PHY address in the ax88772_init_mdio function across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel versions including drivers/net/usb/asix_devices.c before patches in 6.1, 6.6, 6.10, 6.11, and 6.12 branches
  • Siemens SIMATIC CN 4100 before V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later

Timeline

  • 2025-08-18: disclosed: Initial patch submitted by Yuichiro Tsuji
  • 2025-08-28: patched: Patches committed to Linux stable branches
  • 2025-09-05: advisory: CVE published in NVD

References

Related threats