๐Ÿ” CVE Alert

CVE-2026-64228

UNKNOWN 0.0

net: ethtool: phy: avoid NULL deref when PHY driver is unbound

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: ethtool: phy: avoid NULL deref when PHY driver is unbound phydev->drv can become NULL while the phy_device is still attached to its net_device, namely after the PHY driver is unbound via sysfs: echo <mdio_id> > /sys/bus/mdio_bus/drivers/<phy_drv>/unbind phy_remove() clears phydev->drv but doesn't call phy_detach(), so the phy_device stays in the link topology xarray and ethnl_req_get_phydev() still hands it back. ETHTOOL_MSG_PHY_GET then oopses on: rep_data->drvname = kstrdup(phydev->drv->name, GFP_KERNEL); drvname is already treated as optional by phy_reply_size(), phy_fill_reply() and phy_cleanup_data(), so just skip the allocation when there is no driver bound.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 24, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9dd2ad5e92b962d1349a7541d167e8e214e49f95 < 3586924625559e6f9876d726c80ff0a75f0d5849 9dd2ad5e92b962d1349a7541d167e8e214e49f95 < 17fe2381f967d353183f374a1c0181a6d194158c 9dd2ad5e92b962d1349a7541d167e8e214e49f95 < e3adf69f8eb121a9128c2b0029efd050d3649153
Linux / Linux
6.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/3586924625559e6f9876d726c80ff0a75f0d5849 git.kernel.org: https://git.kernel.org/stable/c/17fe2381f967d353183f374a1c0181a6d194158c git.kernel.org: https://git.kernel.org/stable/c/e3adf69f8eb121a9128c2b0029efd050d3649153