SB2025052128 - NULL pointer dereference in Linux kernel net phy driver
Published: May 21, 2025 Updated: May 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-37945)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the phy_link_change() and mdio_bus_phy_suspend() functions in drivers/net/phy/phy_device.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/54e5d00a8de6c13f6c01a94ed48025e882cd15f7
- https://git.kernel.org/stable/c/a6ed6f8ec81b8ca7100dcd9e62bdbc0dff1b2259
- https://git.kernel.org/stable/c/bd4037d51d3f6667636a1383e78e48a5b7b60755
- https://git.kernel.org/stable/c/fc75ea20ffb452652f0d4033f38fe88d7cfdae35
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.24
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.12
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.3