{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-38110", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:23.985Z", "datePublished": "2025-07-03T08:35:19.928Z", "dateUpdated": "2026-08-05T11:59:37.382Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:59:37.382Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mdiobus: Fix potential out-of-bounds clause 45 read/write access\n\nWhen using publicly available tools like 'mdio-tools' to read/write data\nfrom/to network interface and its PHY via C45 (clause 45) mdiobus,\nthere is no verification of parameters passed to the ioctl and\nit accepts any mdio address.\nCurrently there is support for 32 addresses in kernel via PHY_MAX_ADDR define,\nbut it is possible to pass higher value than that via ioctl.\nWhile read/write operation should generally fail in this case,\nmdiobus provides stats array, where wrong address may allow out-of-bounds\nread/write.\n\nFix that by adding address verification before C45 read/write operation.\nWhile this excludes this access from any statistics, it improves security of\nread/write operation." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is reached through SIOCGMIIREG/SIOCSMIIREG ioctls issued on a local socket against a network device, via dev_ioctl() → dev_eth_ioctl() → phylink_mii_ioctl(). No network packet processing is involved, so this is local access only.\nAC:L - The attacker fully controls the 16-bit phy_id field and can deterministically select any out-of-bounds index from 32 to 65535, with no race, timing, or memory-layout condition outside their control; the OOB accounting happens on every call regardless of whether the underlying bus read/write succeeds.\nPR:L - The ioctl path is gated by ns_capable(net->user_ns, CAP_NET_ADMIN), which is namespace-relative rather than requiring real root — an unprivileged user who is root inside a user+network namespace that owns a C45-PHY-backed netdev (SR-IOV VF or DSA user port delegated to a container) satisfies it, so this is Low rather than High.\nUI:N - The attacker triggers the entire sequence themselves with a single ioctl() call; no victim action, mount, or file open is needed.\nS:U - The out-of-bounds access corrupts kernel heap memory from within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - mdiobus_stats_acct() performs a read-modify-write, so it reads 64-bit words at an attacker-chosen offset up to ~2 MB past the mii_bus allocation, and the resulting heap corruption can be groomed to modify length/index fields of adjacent objects to yield arbitrary kernel memory disclosure.\nI:H - The attacker gains a repeatable increment of two 64-bit words at a selectable 32-byte-granular offset far outside the allocation, which after heap grooming allows targeted modification of adjacent kernel objects (refcounts, sizes, pointer bytes) and is a viable path to control-flow hijack.\nA:H - Writing into unrelated slab objects and pages up to ~2 MB beyond the mii_bus allocation corrupts arbitrary kernel state and readily produces oopses, BUG_ONs, or a full panic, and the attacker can repeat it at will." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/phy/mdio_bus.c" ], "versions": [ { "version": "4e4aafcddbbfcdd6eed5780e190fcbfac8b4685a", "lessThan": "abb0605ca00979a49572a6516f6db22c3dc57223", "status": "affected", "versionType": "git" }, { "version": "4e4aafcddbbfcdd6eed5780e190fcbfac8b4685a", "lessThan": "31bf7b2b92563a352788cf9df3698682f659bacc", "status": "affected", "versionType": "git" }, { "version": "4e4aafcddbbfcdd6eed5780e190fcbfac8b4685a", "lessThan": "4ded22f7f3ce9714ed72c3e9c68fea1cb9388ae7", "status": "affected", "versionType": "git" }, { "version": "4e4aafcddbbfcdd6eed5780e190fcbfac8b4685a", "lessThan": "260388f79e94fb3026c419a208ece8358bb7b555", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/phy/mdio_bus.c" ], "versions": [ { "version": "6.3", "status": "affected" }, { "version": "0", "lessThan": "6.3", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.94", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.34", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15.3", "lessThanOrEqual": "6.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.16", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.6.94" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.12.34" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.15.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "6.3", "versionEndExcluding": "6.16" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/abb0605ca00979a49572a6516f6db22c3dc57223" }, { "url": "https://git.kernel.org/stable/c/31bf7b2b92563a352788cf9df3698682f659bacc" }, { "url": "https://git.kernel.org/stable/c/4ded22f7f3ce9714ed72c3e9c68fea1cb9388ae7" }, { "url": "https://git.kernel.org/stable/c/260388f79e94fb3026c419a208ece8358bb7b555" } ], "title": "net/mdiobus: Fix potential out-of-bounds clause 45 read/write access", "x_generator": { "engine": "bippy-1.2.0" } } } }