In the Linux kernel, the following vulnerability has been resolved:
net: usb: asixdevices: add phymask for ax88772 mdio bus
Without setting phymask for ax88772 mdio bus, current driver may create at most 32 mdio phy devices with phy address range from 0x00 ~ 0x1f. DLink DUB-E100 H/W Ver B1 is such a device. However, only one main phy device will bind to net phy driver. This is creating issue during system suspend/resume since phypollingmode() in phystatemachine() will directly deference member of phydev->drv for non-main phy devices. Then NULL pointer dereference issue will occur. Due to only external phy or internal phy is necessary, add phymask for ax88772 mdio bus to workarnoud the issue.
[
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@75947d3200de98a9ded9ad8972e02f1a177097fe",
"digest": {
"line_hashes": [
"147858795047878624839303512418406874008",
"14603828879614283956730307265936207078",
"1322994032900766260384692699507075033",
"43354080113592450461580006943406328410"
],
"threshold": 0.9
},
"id": "CVE-2025-38725-021a5fc0"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@59ed6fbdb1bc03316e09493ffde7066f031c7524",
"digest": {
"line_hashes": [
"147858795047878624839303512418406874008",
"14603828879614283956730307265936207078",
"1322994032900766260384692699507075033",
"325338445675690965284841478481423217320"
],
"threshold": 0.9
},
"id": "CVE-2025-38725-0beb6ad4"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@59ed6fbdb1bc03316e09493ffde7066f031c7524",
"digest": {
"length": 635.0,
"function_hash": "966138410105339065727621783359772741"
},
"id": "CVE-2025-38725-0f444e9b"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ccef5ee4adf56472aa26bdd1f821a6d0cd06089a",
"digest": {
"length": 635.0,
"function_hash": "966138410105339065727621783359772741"
},
"id": "CVE-2025-38725-149df58e"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ee2cd40b0bb46056949a2319084a729d95389386",
"digest": {
"line_hashes": [
"147858795047878624839303512418406874008",
"14603828879614283956730307265936207078",
"1322994032900766260384692699507075033",
"325338445675690965284841478481423217320"
],
"threshold": 0.9
},
"id": "CVE-2025-38725-2cc29d6e"
},
{
"signature_type": "Line",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ccef5ee4adf56472aa26bdd1f821a6d0cd06089a",
"digest": {
"line_hashes": [
"147858795047878624839303512418406874008",
"14603828879614283956730307265936207078",
"1322994032900766260384692699507075033",
"325338445675690965284841478481423217320"
],
"threshold": 0.9
},
"id": "CVE-2025-38725-3a9d63f1"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@75947d3200de98a9ded9ad8972e02f1a177097fe",
"digest": {
"length": 523.0,
"function_hash": "134850073837294041212359509109601371375"
},
"id": "CVE-2025-38725-93cfc0bf"
},
{
"signature_type": "Function",
"deprecated": false,
"target": {
"file": "drivers/net/usb/asix_devices.c",
"function": "ax88772_init_mdio"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@ee2cd40b0bb46056949a2319084a729d95389386",
"digest": {
"length": 635.0,
"function_hash": "966138410105339065727621783359772741"
},
"id": "CVE-2025-38725-da29620c"
}
]