SB2025070491 - Improper error handling in Linux kernel stmicro stmmac driver
Published: July 4, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2025-38126)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the stmmac_ptp_register() function in drivers/net/ethernet/stmicro/stmmac/stmmac_ptp.c, within the stmmac_init_tstamp_counter() function in drivers/net/ethernet/stmicro/stmmac/stmmac_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/030ce919e114a111e83b7976ecb3597cefd33f26
- https://git.kernel.org/stable/c/32af9c289234990752281c805500dfe03c5b2b8f
- https://git.kernel.org/stable/c/379cd990dfe752b38fcf46034698a9a150626c7a
- https://git.kernel.org/stable/c/b263088ee8ab14563817a8be3519af8e25225793
- https://git.kernel.org/stable/c/bb033c6781ce1b0264c3993b767b4aa9021959c2