CVE-2025-71196
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/02/2026
Last modified:
04/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
phy: stm32-usphyc: Fix off by one in probe()<br />
<br />
The "index" variable is used as an index into the usbphyc->phys[] array<br />
which has usbphyc->nphys elements. So if it is equal to usbphyc->nphys<br />
then it is one element out of bounds. The "index" comes from the<br />
device tree so it&#39;s data that we trust and it&#39;s unlikely to be wrong,<br />
however it&#39;s obviously still worth fixing the bug. Change the > to >=.



