Denial of Service in Linux Kernel Due to Generic PHY LED Registration
CVE-2025-38537
What is CVE-2025-38537?
A significant vulnerability affecting the Linux kernel has been identified regarding LED registration for generic PHYs. When a generic PHY does not have an associated driver, it may trigger a deadlock when probing or removing the genphy driver. This occurs because LEDs associated with a non-generic driver are incorrectly registered or unregistered, leading to a situation where kernel threads are unable to proceed, ultimately causing a denial of service. This issue emphasizes the importance of ensuring that generic PHYs do not involve unnecessary LED registrations, as they do not inherently support such features.
Affected Version(s)
Linux 01e5b728e9e43ae444e0369695a5f72209906464
Linux 01e5b728e9e43ae444e0369695a5f72209906464
Linux 01e5b728e9e43ae444e0369695a5f72209906464 < 75e1b2079ef0653a2f7aa69be515d86b7faf1908