CVE-2026-98008
In the Linux kernel, the following vulnerability has been resolved:
net: macb: fix NULL pointer dereference on unbind with fixed-link
When the device tree describes a fixed-link and has no "mdio" child node, macb_mii_init() returns early without allocating the MDIO bus, leaving bp->mii_bus as NULL.
Two cleanup paths then dereference this NULL bus:
mdiobus_unregister() and mdiobus_free() do not guard against a NULL bus, so guard the calls in both macb_remove() and the probe error path.
Detalles técnicos trazas, registros y código del informe original
1. On driver unbind, macb_remove() unconditionally calls mdiobus_unregister(bp->mii_bus), which oopses: Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8 pc : mdiobus_unregister+0x14/0xa4 lr : macb_remove+0x38/0xa4 Call trace: mdiobus_unregister+0x14/0xa4 (P) macb_remove+0x38/0xa4 platform_remove+0x20/0x30 device_release_driver_internal+0x1c8/0x224 unbind_store+0xb4/0xbc 2. On the probe error path in macb_probe(), reached when macb_mii_init() has succeeded but a subsequent step fails, the err_out_unregister_mdio label runs the same unconditional cleanup.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/054ad8e66025eb4778d840bef80c270646cebcd2
- https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a
- https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4
- https://git.kernel.org/stable/c/afa224cabc0132ca414b9141b1a919ca2d318cd0
- https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3
- https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-98008",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "831e19e565b5210930fa183730071f8290c61263",
"lessThan": "afa224cabc0132ca414b9141b1a919ca2d318cd0",
"versionType": "git"
},
{
"status": "affected",
"version": "81db1e52848694761a1aa162ce76198af9964ed8",
"lessThan": "054ad8e66025eb4778d840bef80c270646cebcd2",
"versionType": "git"
},
{
"status": "affected",
"version": "d0c3601f2c4e12e7689b0f46ebc17525250ea8c3",
"lessThan": "f737d999fcb8f276d77b01ea4c2016ee01dad19b",
"versionType": "git"
},
{
"status": "affected",
"version": "d0c3601f2c4e12e7689b0f46ebc17525250ea8c3",
"lessThan": "5710f6a74f63cbba0e15cd75917234916181c9d4",
"versionType": "git"
},
{
"status": "affected",
"version": "d0c3601f2c4e12e7689b0f46ebc17525250ea8c3",
"lessThan": "edb39c7666bb3924da761dfb417db85c1e5d8ad3",
"versionType": "git"
},
{
"status": "affected",
"version": "d0c3601f2c4e12e7689b0f46ebc17525250ea8c3",
"lessThan": "38b6be101006d3e7af972999f45d4f1e8250587a",
"versionType": "git"
},
{
"status": "affected",
"version": "cafa5942bd2df3d80e3eeb2deb4bc050f7761f3d",
"versionType": "git"
},
{
"status": "affected",
"version": "c81dcaa9cd0b66816c2ecb6c5df0b6afde9c7da5",
"versionType": "git"
},
{
"status": "affected",
"version": "19088c5378c9fea54e552d8bc7418a3aa1e06990",
"versionType": "git"
},
{
"status": "affected",
"version": "6.1.114",
"lessThan": "6.1.189",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.6.58",
"lessThan": "6.6.158",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.10.228",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "affected",
"version": "5.15.169",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.11.5",
"lessThan": "6.12",
"versionType": "semver"
}
],
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.12",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.189",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.53",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.7",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc3",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/ethernet/cadence/macb_main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-25T11:17:29.080",
"references": [
{
"url": "https://git.kernel.org/stable/c/054ad8e66025eb4778d840bef80c270646cebcd2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/afa224cabc0132ca414b9141b1a919ca2d318cd0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns early without allocating the MDIO bus,\nleaving bp->mii_bus as NULL.\n\nTwo cleanup paths then dereference this NULL bus:\n\n1. On driver unbind, macb_remove() unconditionally calls\n mdiobus_unregister(bp->mii_bus), which oopses:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8\n pc : mdiobus_unregister+0x14/0xa4\n lr : macb_remove+0x38/0xa4\n Call trace:\n mdiobus_unregister+0x14/0xa4 (P)\n macb_remove+0x38/0xa4\n platform_remove+0x20/0x30\n device_release_driver_internal+0x1c8/0x224\n unbind_store+0xb4/0xbc\n\n2. On the probe error path in macb_probe(), reached when\n macb_mii_init() has succeeded but a subsequent step fails, the\n err_out_unregister_mdio label runs the same unconditional cleanup.\n\nmdiobus_unregister() and mdiobus_free() do not guard against a NULL\nbus, so guard the calls in both macb_remove() and the probe error\npath."
}
],
"lastModified": "2026-10-03T11:18:23.743",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}