CVE-2025-38272

MEDIUM

Linux Kernel 4.15-6.12.45, 6.13-6.15.2 - Denial of Service via EEE Configuration on BCM63xx Switches

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: b53: do not enable EEE on bcm63xx BCM63xx internal switches do not support EEE, but provide multiple RGMII ports where external PHYs may be connected. If one of these PHYs are EEE capable, we may try to enable EEE for the MACs, which then hangs the system on access of the (non-existent) EEE registers. Fix this by checking if the switch actually supports EEE before attempting to configure it.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 5.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (11)
linux/Kernel 4.15.0 - 6.12.46linux
linux/Kernel 6.13.0 - 6.15.3linux
Linux/Linux < 4.15
Linux/Linux 22256b0afb12333571ad11799fa68fd27e4f4e80 - 1237c2d4a8db79dfd4369bff6930b0e385ed7d5c
Linux/Linux 22256b0afb12333571ad11799fa68fd27e4f4e80 - 2dbccf1eb8c04b84ee3afdb1d6b787db02e7befc
Linux/Linux 22256b0afb12333571ad11799fa68fd27e4f4e80 - 3fbe3f4c57fda09f32e13fa05f53a0cc6f500619
Linux/Linux 4.15
Linux/Linux 6.12.46 - 6.12.*
Linux/Linux 6.15.3 - 6.15.*
Linux/Linux 6.16
... and 1 more
Published Jul 10, 2025
Tracked Since Feb 18, 2026