PT-2025-27293 · Linux+8 · Linux Kernel+8

CVE-2025-38086

·

Publicado

2025-06-28

·

Atualizado

2026-08-25

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A vulnerability in the Linux kernel has been identified, specifically in the ch9200 network driver. The issue arises from the mii nway restart() function, which calls mii->mdio read, also known as ch9200 mdio read(). This function uses a local buffer called buff, initialized by control read(). However, buff is conditionally initialized, and if the condition err == size is not met, buff remains uninitialized. As a result, buff is accessed and returned during ch9200 mdio read(), leading to uninitialized access. The problem is caused by ch9200 mdio read() ignoring the return value of control read(), resulting in uninitialized access of buff.
Recommendations: To fix this issue, check the return value of control read() and return early on error in the ch9200 mdio read() function.

Exploit

Correção

DoS

Use of Uninitialized Resource

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025:11455
ALSA-2025:11456
ALSA-2025:11861
ALSA-2025:12662
AZL-64383
BDU:2025-09834
CESA-2025_11455
CESA-2025_11456
CVE-2025-38086
DLA-4327-1
DLA-4328-1
DSA-5973-1
ECHO-6B2B-9F73-98C9
INFSA-2025_11455
INFSA-2025_11456
INFSA-2025_11861
MGASA-2025-0218
MGASA-2025-0219
OESA-2025-2080
OESA-2025-2407
OESA-2025-2408
OESA-2025-2465
OESA-2025-2466
OESA-2025-2467
RHSA-2025:11455
RHSA-2025:11456
RHSA-2025:11861
RHSA-2025:12662
RHSA-2025:13633
RHSA-2025:13776
RHSA-2025:13781
RHSA-2025:13805
RHSA-2025:13946
RHSA-2025:14054
RHSA-2025:14094
RHSA-2025:14136
RHSA-2025:14418
RHSA-2025_11455
RHSA-2025_11456
RHSA-2025_11861
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7833-1
USN-7833-2
USN-7833-3
USN-7833-4
USN-7834-1
USN-7856-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Produtos afetados

Almalinux
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Ubuntu