In the Linux kernel, the following vulnerability has been resolved:
net/mdiobus: Fix potential out-of-bounds read/write access
When using publicly available tools like 'mdio-tools' to read/write data from/to network interface and its PHY via mdiobus, there is no verification of parameters passed to the ioctl and it accepts any mdio address. Currently there is support for 32 addresses in kernel via PHYMAXADDR define, but it is possible to pass higher value than that via ioctl. While read/write operation should generally fail in this case, mdiobus provides stats array, where wrong address may allow out-of-bounds read/write.
Fix that by adding address verification before read/write operation. While this excludes this access from any statistics, it improves security of read/write operation.
[
    {
        "signature_version": "v1",
        "digest": {
            "length": 355.0,
            "function_hash": "85906014803464935113768350693372344392"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-2845f395",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_write"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@014ad9210373d2104f6ef10e6bb999a7a0a4c50e",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 355.0,
            "function_hash": "85906014803464935113768350693372344392"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-5881862a",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_write"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e629694126ca388916f059453a1c36adde219c4",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "102353093615510223682626166001617381357",
                "146579822832702516355111815955133841846",
                "78663403592276225841052043995987542480",
                "195487212993155212711101340449226514576",
                "91300728437180057983336031371437834293",
                "190446435133510806585471430979460285314"
            ]
        },
        "signature_type": "Line",
        "id": "CVE-2025-38111-6e076d61",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@014ad9210373d2104f6ef10e6bb999a7a0a4c50e",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "102353093615510223682626166001617381357",
                "146579822832702516355111815955133841846",
                "78663403592276225841052043995987542480",
                "195487212993155212711101340449226514576",
                "91300728437180057983336031371437834293",
                "190446435133510806585471430979460285314"
            ]
        },
        "signature_type": "Line",
        "id": "CVE-2025-38111-8523185d",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e629694126ca388916f059453a1c36adde219c4",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "102353093615510223682626166001617381357",
                "146579822832702516355111815955133841846",
                "78663403592276225841052043995987542480",
                "195487212993155212711101340449226514576",
                "91300728437180057983336031371437834293",
                "190446435133510806585471430979460285314"
            ]
        },
        "signature_type": "Line",
        "id": "CVE-2025-38111-85a0ef05",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bab6bca0834cbb5be2a7cfe59ec6ad016ec72608",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 328.0,
            "function_hash": "299484094075590469261952263632071004459"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-961663b7",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_read"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@73d478234a619f3476028cb02dee699c30ae8262",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 328.0,
            "function_hash": "299484094075590469261952263632071004459"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-9e5cbfd2",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_read"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0e629694126ca388916f059453a1c36adde219c4",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 355.0,
            "function_hash": "85906014803464935113768350693372344392"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-a537591d",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_write"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@73d478234a619f3476028cb02dee699c30ae8262",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 355.0,
            "function_hash": "85906014803464935113768350693372344392"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-abfe14b4",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_write"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bab6bca0834cbb5be2a7cfe59ec6ad016ec72608",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 328.0,
            "function_hash": "299484094075590469261952263632071004459"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-d8bb243c",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_read"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@014ad9210373d2104f6ef10e6bb999a7a0a4c50e",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "length": 328.0,
            "function_hash": "299484094075590469261952263632071004459"
        },
        "signature_type": "Function",
        "id": "CVE-2025-38111-df2288a2",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c",
            "function": "__mdiobus_read"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@bab6bca0834cbb5be2a7cfe59ec6ad016ec72608",
        "deprecated": false
    },
    {
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "102353093615510223682626166001617381357",
                "146579822832702516355111815955133841846",
                "78663403592276225841052043995987542480",
                "195487212993155212711101340449226514576",
                "91300728437180057983336031371437834293",
                "190446435133510806585471430979460285314"
            ]
        },
        "signature_type": "Line",
        "id": "CVE-2025-38111-fd628eb3",
        "target": {
            "file": "drivers/net/phy/mdio_bus.c"
        },
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@73d478234a619f3476028cb02dee699c30ae8262",
        "deprecated": false
    }
]