CVE-2025-38272
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/07/2025
Last modified:
20/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
net: dsa: b53: do not enable EEE on bcm63xx<br />
<br />
BCM63xx internal switches do not support EEE, but provide multiple RGMII<br />
ports where external PHYs may be connected. If one of these PHYs are EEE<br />
capable, we may try to enable EEE for the MACs, which then hangs the<br />
system on access of the (non-existent) EEE registers.<br />
<br />
Fix this by checking if the switch actually supports EEE before<br />
attempting to configure it.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 4.15 (including) | 6.12.46 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.15.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



