In the Linux kernel, the following vulnerability has been resolved: net: macb: fix NULL pointer...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix NULL pointer dereference on unbind with fixed-link
When the device tree describes a fixed-link and has no "mdio" child node, macb_mii_init() returns early without allocating the MDIO bus, leaving bp->mii_bus as NULL.
Two cleanup paths then dereference this NULL bus:
- On driver unbind, macb_remove() unconditionally calls mdiobus_unregister(bp->mii_bus), which oopses:
Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8 pc : mdiobus_unregister+0x14/0xa4 lr : macb_remove+0x38/0xa4 Call trace: mdiobus_unregister+0x14/0xa4 (P) macb_remove+0x38/0xa4 platform_remove+0x20/0x30 device_release_driver_internal+0x1c8/0x224 unbind_store+0xb4/0xbc
- On the probe error path in macb_probe(), reached when macb_mii_init() has succeeded but a subsequent step fails, the err_out_unregister_mdio label runs the same unconditional cleanup.
mdiobus_unregister() and mdiobus_free() do not guard against a NULL bus, so guard the calls in both macb_remove() and the probe error path.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-98008
- https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a
- https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4
- https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3
- https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b
- https://git.kernel.org/stable/c/054ad8e66025eb4778d840bef80c270646cebcd2
- https://git.kernel.org/stable/c/afa224cabc0132ca414b9141b1a919ca2d318cd0
- https://github.com/advisories/GHSA-h4xg-972w-f7c3