CVE-2025-38148 is a memory leak vulnerability in the Linux kernel's network PHY driver for MSCC devices, specifically impacting one-step timestamping functionality. This flaw affects various Debian and Linux kernel versions. Rated as Medium severity (CVSS 5.5), it has a local attack vector with low complexity, requiring local privileges but no user interaction, and can lead to high availability impact due to resource exhaustion. There is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered some community discussion and media coverage, as indicated by two mentions and two articles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.9, < 5.15.192CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.142CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.94CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.7, < 6.12.34CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.15.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026net: phy: mscc: Fix memory leak when using one step timestamping
Jul 8, 2025kernel: net: phy: mscc: Fix memory leak when using one step timestamping
Jul 3, 2025