CVE Vulnerabilities

CVE-2025-71196

Published: Feb 04, 2026 | Modified: Feb 04, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In the Linux kernel, the following vulnerability has been resolved:

phy: stm32-usphyc: Fix off by one in probe()

The index variable is used as an index into the usbphyc->phys[] array which has usbphyc->nphys elements. So if it is equal to usbphyc->nphys then it is one element out of bounds. The index comes from the device tree so its data that we trust and its unlikely to be wrong, however its obviously still worth fixing the bug. Change the > to >=.

References