CVE-2026-98008 PUBLISHED

net: macb: fix NULL pointer dereference on unbind with fixed-link

Assigner: Linux
Reserved: 25.09.2026 Published: 25.09.2026 Updated: 25.09.2026

In the Linux kernel, the following vulnerability has been resolved:

net: macb: fix NULL pointer dereference on unbind with fixed-link

When the device tree describes a fixed-link and has no "mdio" child node, macb_mii_init() returns early without allocating the MDIO bus, leaving bp->mii_bus as NULL.

Two cleanup paths then dereference this NULL bus:

  1. On driver unbind, macb_remove() unconditionally calls mdiobus_unregister(bp->mii_bus), which oopses:

Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8 pc : mdiobus_unregister+0x14/0xa4 lr : macb_remove+0x38/0xa4 Call trace: mdiobus_unregister+0x14/0xa4 (P) macb_remove+0x38/0xa4 platform_remove+0x20/0x30 device_release_driver_internal+0x1c8/0x224 unbind_store+0xb4/0xbc

  1. On the probe error path in macb_probe(), reached when macb_mii_init() has succeeded but a subsequent step fails, the err_out_unregister_mdio label runs the same unconditional cleanup.

mdiobus_unregister() and mdiobus_free() do not guard against a NULL bus, so guard the calls in both macb_remove() and the probe error path.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 to f737d999fcb8f276d77b01ea4c2016ee01dad19b (excl.)
  • affected from d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 to 5710f6a74f63cbba0e15cd75917234916181c9d4 (excl.)
  • affected from d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 to edb39c7666bb3924da761dfb417db85c1e5d8ad3 (excl.)
  • affected from d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 to 38b6be101006d3e7af972999f45d4f1e8250587a (excl.)
  • Version cafa5942bd2df3d80e3eeb2deb4bc050f7761f3d is affected
  • Version c81dcaa9cd0b66816c2ecb6c5df0b6afde9c7da5 is affected
  • Version 831e19e565b5210930fa183730071f8290c61263 is affected
  • Version 81db1e52848694761a1aa162ce76198af9964ed8 is affected
  • Version 19088c5378c9fea54e552d8bc7418a3aa1e06990 is affected
  • affected from 5.10.228 to 5.11 (excl.)
  • affected from 5.15.169 to 5.16 (excl.)
  • affected from 6.1.114 to 6.2 (excl.)
  • affected from 6.6.58 to 6.7 (excl.)
  • affected from 6.11.5 to 6.12 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.12 is affected
  • unaffected from 0 to 6.12 (excl.)
  • unaffected from 6.12.111 to 6.12.* (incl.)
  • unaffected from 6.18.53 to 6.18.* (incl.)
  • unaffected from 7.2.7 to 7.2.* (incl.)
  • unaffected from 7.3-rc3 to * (incl.)

References