CVE-2026-98008
Last modified
CVE-2026-98008 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: macb: fix NULL pointer dereference on unbind with fixed-link When the device tree describes a fixed-link and has no "mdio" child node, macb_mii_init() returns early without allocating the MDIO bus, leaving bp->mii_bus as NULL. Two cleanup paths then dereference this NULL bus: 1. On driver unbind, macb_remove() unconditionally calls mdiobus_unregister(bp->mii_bus), which oopses: Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8 pc : mdiobus_unregister+0x14/0xa4 lr : macb_remove+0x38/0xa4 Call trace: mdiobus_unregister+0x14/0xa4 (P) macb_remove+0x38/0xa4 platform_remove+0x20/0x30 device_release_driver_internal+0x1c8/0x224 unbind_store+0xb4/0xbc 2.
Description
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix NULL pointer dereference on unbind with fixed-link When the device tree describes a fixed-link and has no "mdio" child node, macb_mii_init() returns early without allocating the MDIO bus, leaving bp->mii_bus as NULL. Two cleanup paths then dereference this NULL bus: 1. On driver unbind, macb_remove() unconditionally calls mdiobus_unregister(bp->mii_bus), which oopses: Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8 pc : mdiobus_unregister+0x14/0xa4 lr : macb_remove+0x38/0xa4 Call trace: mdiobus_unregister+0x14/0xa4 (P) macb_remove+0x38/0xa4 platform_remove+0x20/0x30 device_release_driver_internal+0x1c8/0x224 unbind_store+0xb4/0xbc 2. On the probe error path in macb_probe(), reached when macb_mii_init() has succeeded but a subsequent step fails, the err_out_unregister_mdio label runs the same unconditional cleanup. mdiobus_unregister() and mdiobus_free() do not guard against a NULL bus, so guard the calls in both macb_remove() and the probe error path.
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3, < f737d999fcb8f276d77b01ea4c2016ee01dad19b; >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3, < 5710f6a74f63cbba0e15cd75917234916181c9d4; >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3, < edb39c7666bb3924da761dfb417db85c1e5d8ad3; >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3, < 38b6be101006d3e7af972999f45d4f1e8250587a; cafa5942bd2df3d80e3eeb2deb4bc050f7761f3d; c81dcaa9cd0b66816c2ecb6c5df0b6afde9c7da5; 831e19e565b5210930fa183730071f8290c61263; 81db1e52848694761a1aa162ce76198af9964ed8; 19088c5378c9fea54e552d8bc7418a3aa1e06990; >= 5.10.228, < 5.11; >= 5.15.169, < 5.16; >= 6.1.114, < 6.2; >= 6.6.58, < 6.7; >= 6.11.5, < 6.12 |
| Linux | Linux | 6.12 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-98008?
How severe is CVE-2026-98008?
How do I fix CVE-2026-98008?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-98002In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-98003In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98004In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98005In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98006In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98007In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98009In the Linux kernel, the following vulnerability has been re…
- CVE-2026-9801A flaw was found in Keycloak. A remote attacker with high pr…4.9
- CVE-2026-98010In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98011In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98012In the Linux kernel, the following vulnerability has been re…
- CVE-2026-98013In the Linux kernel, the following vulnerability has been re…
Are you affected by CVE-2026-98008?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
