Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-71094— net: usb: asix: validate PHY address before use

AI Predicted 5.5 Difficulty: Easy EPSS 0.12% · P2

Possible ATT&CK Techniques 1AI

T1200.001

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux7e88b11a862afe59ee0c365123ea5fb96a26cb3b< fc96018f09f8d30586ca6582c5045a84eafef146affected
7e88b11a862afe59ee0c365123ea5fb96a26cb3b< f5f4f30f3811d37e1aa48667c36add74e5a8d99faffected
7e88b11a862afe59ee0c365123ea5fb96a26cb3b< 38722e69ee64dbb020028c93898d25d6f4c0e0b2affected
7e88b11a862afe59ee0c365123ea5fb96a26cb3b< 98a12c2547a44a5f03f35c108d2022cc652cbc4daffected
7e88b11a862afe59ee0c365123ea5fb96a26cb3b< bf8a0f3b787ca7c5889bfca12c60c483041fbee3affected
7e88b11a862afe59ee0c365123ea5fb96a26cb3b< a1e077a3f76eea0dc671ed6792e7d543946227e8affected
4e4f3cb41d687bd64cd03358862b23c84d82329eaffected
5.13.13< 5.14affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-71094

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: usb: asix: validate PHY address before use
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: usb: asix: validate PHY address before use The ASIX driver reads the PHY address from the USB device via asix_read_phy_addr(). A malicious or faulty device can return an invalid address (>= PHY_MAX_ADDR), which causes a warning in mdiobus_get_phy(): addr 207 out of range WARNING: drivers/net/phy/mdio_bus.c:76 Validate the PHY address in asix_read_phy_addr() and remove the now-redundant check in ax88172a.c.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于asix_read_phy_addr函数未验证PHY地址,可能导致无效地址使用。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 7e88b11a862afe59ee0c365123ea5fb96a26cb3b ~ fc96018f09f8d30586ca6582c5045a84eafef146 -
LinuxLinux 5.14 -

II. Public POCs for CVE-2025-71094

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-71094

登录查看更多情报信息。

Same Patch Batch · Linux · 2026-01-13 · 93 CVEs total

CVE-2025-710689.8 CRITICALsvcrdma: bound check rq_pages index in inline path
CVE-2025-687759.8 CRITICALnet/handshake: duplicate handshake cancellations leak socket
CVE-2025-688179.8 CRITICALksmbd: fix use-after-free in ksmbd_tree_connect_put under concurrency
CVE-2025-687949.8 CRITICALiomap: adjust read range correctly for non-block-aligned positions
CVE-2025-688119.8 CRITICALsvcrdma: use rc_pageoff for memcpy byte offset
CVE-2025-688099.1 CRITICALksmbd: vfs: fix race on m_flags in vfs_cache
CVE-2025-710959.1 CRITICALnet: stmmac: fix the crash issue for zero copy XDP_TX action
CVE-2025-710939.1 CRITICALe1000: fix OOB in e1000_tbi_should_accept()
CVE-2025-688188.8 HIGHscsi: Revert "scsi: qla2xxx: Perform lockless command completion in abort path"
CVE-2025-710728.2 HIGHshmem: fix recovery on rename failures
CVE-2025-687998.1 HIGHcaif: fix integer underflow in cffrml_receive()
CVE-2025-688038.0 HIGHNFSD: NFSv4 file creation neglects setting ACL
CVE-2025-688197.8 HIGHmedia: dvb-usb: dtv5100: fix out-of-bounds in dtv5100_i2c_msg()
CVE-2025-688157.8 HIGHnet/sched: ets: Remove drr class from the active list if it changes to strict
CVE-2025-710667.8 HIGHnet/sched: ets: Always remove class from active list before deleting in ets_qdisc_change
CVE-2025-688227.8 HIGHInput: alps - fix use-after-free bugs caused by dev3_register_work
CVE-2025-687927.8 HIGHtpm2-sessions: Fix out of range indexing in name_size
CVE-2025-687937.8 HIGHdrm/amdgpu: fix a job->pasid access race in gpu recovery
CVE-2025-710747.8 HIGHfunctionfs: fix the open/removal races
CVE-2025-687957.8 HIGHethtool: Avoid overflowing userspace buffer on stats query

Showing top 20 of 93 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-71094

No comments yet


Leave a comment