Back

MEDIUM

net: usb: asix: validate PHY address before use

Published Jan 13, 2026

Description

The ASIX driver reads the PHY address from the USB device via asix_read_phy_addr(). A malicious or faulty device can return an invalid address (>= PHY_MAX_ADDR), which causes a warning in mdiobus_get_phy():

addr 207 out of range WARNING: drivers/net/phy/mdio_bus.c:76

Validate the PHY address in asix_read_phy_addr() and remove the now-redundant check in ax88172a.c.

Affected products

Remediation

Red Hat statement

This vulnerability requires physical access to connect a malicious USB device. The impact is limited to a kernel warning message; the invalid address is rejected before it can cause further damage. While the warning indicates a potential issue, it does not result in a crash or security compromise.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jan 13, 2026
Updated Jun 11, 2026
Reserved Jan 13, 2026
CISA Vulnrichment
Updated Jun 10, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 13, 2026