Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on device. Also prevent out-of-bound read/write.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 4.19, < 6.1.142 |
| Debian | Debian Linux | 11.0 |
References
- https://git.kernel.org/stable/c/088279ff18cdc437d6fac5890e0c52c624f78a5bPatch
- https://git.kernel.org/stable/c/3b9935586a9b54d2da27901b830d3cf46ad66a1ePatch
- https://git.kernel.org/stable/c/51318d644c993b3f7a60b8616a6a5adc1e967cd2Patch
- https://git.kernel.org/stable/c/6b4201d74d0a49af2123abf2c9d142e59566714bPatch
- https://git.kernel.org/stable/c/9c41d2a2aa3817946eb613522200cab55513ddaaPatch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlMailing ListThird Party Advisory
FAQ
What is CVE-2025-38422?
CVE-2025-38422 is a vulnerability with a CVSS score of 7.8 (HIGH). In the Linux kernel, the following vulnerability has been resolved: net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are...
How severe is CVE-2025-38422?
CVE-2025-38422 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-38422?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.