net: lan743x: Modify the EEPROM and OTP size for PCI1xxxx devices
Published Jul 25, 2025
7.8
HIGHCVSS 3.1
EPSS 0.18%
Description
Maximum OTP and EEPROM size for hearthstone PCI1xxxx devices are 8 Kb and 64 Kb respectively. Adjust max size definitions and return correct EEPROM length based on device. Also prevent out-of-bound read/write.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 4.19StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<4.19
- Version 6.1.142StatusunaffectedConstraints<=6.1.*
- Version 6.12.35StatusunaffectedConstraints<=6.12.*
- Version 6.15.4StatusunaffectedConstraints<=6.15.*
- Version 6.16StatusunaffectedConstraints<=*
- Version 6.6.95StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 4.19 · < 6.1.142
- ≥ 6.2 · < 6.6.95
- ≥ 6.7 · < 6.12.35
- ≥ 6.13 · < 6.15.4
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A vulnerability in the lan743x Ethernet driver allowed out-of-bounds read/write access to EEPROM and OTP memory on Microchip PCI1xxxx-based devices due to improper bounds checking. This could lead to system instability or denial of service when exploited by a privileged local attacker. The vulnerability is mitigated by introducing correct size limits and validating access ranges. Privileges Required: High, as the attacker needs administrative access (e.g., via ethtool). The vulnerability is only relevant on systems using the lan743x driver with PCI1xxxx devices. Privileges Required is set to High because triggering the vulnerability requires administrative access, such as root privileges, to execute ethtool operations or access ioctl interfaces capable of invoking EEPROM or OTP read/write routines within the lan743x driver. Not actual for the Red Hat Enterprise Linux (all versions), so not affected.
Red Hat mitigation
Support for the Microchip LAN743x and PCI11x1x families of PCI is disabled for all versions of Red Hat Enterprise Linux, so mitigation not required.
References (12)
- https://access.redhat.com/security/cve/CVE-2025-38422 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2383465 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-22663 Advisory
- https://git.kernel.org/stable/c/088279ff18cdc437d6fac5890e0c52c624f78a5b Patch
- https://git.kernel.org/stable/c/3b9935586a9b54d2da27901b830d3cf46ad66a1e Patch
- https://git.kernel.org/stable/c/51318d644c993b3f7a60b8616a6a5adc1e967cd2 Patch
- https://git.kernel.org/stable/c/6b4201d74d0a49af2123abf2c9d142e59566714b Patch
- https://git.kernel.org/stable/c/9c41d2a2aa3817946eb613522200cab55513ddaa Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Mailing ListThird Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025072554-CVE-2025-38422-5d9b@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38422
- https://www.cve.org/CVERecord?id=CVE-2025-38422
Change history (0)
No recorded changes yet.