VYPR
High severity7.8NVD Advisory· Published Jul 25, 2025· Updated Jul 30, 2026

CVE-2025-38422

CVE-2025-38422

Description

In the Linux kernel, the following vulnerability has been resolved:

net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices

Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on device. Also prevent out-of-bound read/write.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
  • Linux/Kernel3 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=4.19,<6.1.142
    • (no CPE)
    • (no CPE)range: 4.19
  • osv-coords
    Range: >= 4.19.0, < 6.1.142

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.