CVE-2025-71196
In the Linux kernel, the following vulnerability has been resolved:
phy: stm32-usphyc: Fix off by one in probe()
The "index" variable is used as an index into the usbphyc->phys[] array which has usbphyc->nphys elements. So if it is equal to usbphyc->nphys then it is one element out of bounds. The "index" comes from the device tree so it's data that we trust and it's unlikely to be wrong, however it's obviously still worth fixing the bug. Change the > to >=.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/76b870fdaad82171a24b8aacffe5e4d9e0d2ee2c
- https://git.kernel.org/stable/c/7c27eaf183563b86d815ff6e9cca0210b4cfa051
- https://git.kernel.org/stable/c/a9eec890879731c280697fdf1c50699e905b2fa7
- https://git.kernel.org/stable/c/b91c9f6bfb04e430adeeac7e7ebc9d80f9d72bad
- https://git.kernel.org/stable/c/c06f13876cbad702582cd67fc77356e5524d02cd
- https://git.kernel.org/stable/c/cabd25b57216ddc132efbcc31f972baa03aad15a
- https://git.kernel.org/stable/c/fb9d513cdf1614bf0f0e785816afb1faae3f81af
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-71196",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "a9eec890879731c280697fdf1c50699e905b2fa7",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "fb9d513cdf1614bf0f0e785816afb1faae3f81af",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "c06f13876cbad702582cd67fc77356e5524d02cd",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "76b870fdaad82171a24b8aacffe5e4d9e0d2ee2c",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "b91c9f6bfb04e430adeeac7e7ebc9d80f9d72bad",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "7c27eaf183563b86d815ff6e9cca0210b4cfa051",
"versionType": "git"
},
{
"status": "affected",
"version": "94c358da3a0545205c6c6a50ae26141f1c73acfa",
"lessThan": "cabd25b57216ddc132efbcc31f972baa03aad15a",
"versionType": "git"
}
],
"programFiles": [
"drivers/phy/st/phy-stm32-usbphyc.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.249",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.199",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.162",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.122",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.67",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.7",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/phy/st/phy-stm32-usbphyc.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-02-04T17:16:11.530",
"references": [
{
"url": "https://git.kernel.org/stable/c/76b870fdaad82171a24b8aacffe5e4d9e0d2ee2c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7c27eaf183563b86d815ff6e9cca0210b4cfa051",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a9eec890879731c280697fdf1c50699e905b2fa7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b91c9f6bfb04e430adeeac7e7ebc9d80f9d72bad",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/c06f13876cbad702582cd67fc77356e5524d02cd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cabd25b57216ddc132efbcc31f972baa03aad15a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/fb9d513cdf1614bf0f0e785816afb1faae3f81af",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Deferred",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nphy: stm32-usphyc: Fix off by one in probe()\n\nThe \"index\" variable is used as an index into the usbphyc->phys[] array\nwhich has usbphyc->nphys elements. So if it is equal to usbphyc->nphys\nthen it is one element out of bounds. The \"index\" comes from the\ndevice tree so it's data that we trust and it's unlikely to be wrong,\nhowever it's obviously still worth fixing the bug. Change the > to >=."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nphy: stm32-usphyc: Corrección de un error 'off by one' en probe()\n\nLa variable 'index' se utiliza como índice en el array usbphyc->phys[] que tiene usbphyc->nphys elementos. Así que si es igual a usbphyc->nphys, entonces está un elemento fuera de los límites. El 'index' proviene del árbol de dispositivos, por lo que son datos en los que confiamos y es poco probable que sea incorrecto; sin embargo, obviamente, aún vale la pena corregir el error. Cambiar el > por >=."
}
],
"lastModified": "2026-06-17T10:03:52.030",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}