CVE-2026-64228 Details
Description
In the Linux kernel, the following vulnerability has been resolved: net: ethtool: phy: avoid NULL deref when PHY driver is unbound phydev->drv can become NULL while the phy_device is still attached to its net_device, namely after the PHY driver is unbound via sysfs: echo <mdio_id> > /sys/bus/mdio_bus/drivers/<phy_drv>/unbind phy_remove() clears phydev->drv but doesn't call phy_detach(), so the phy_device stays in the link topology xarray and ethnl_req_get_phydev() still hands it back. ETHTOOL_MSG_PHY_GET then oopses on: rep_data->drvname = kstrdup(phydev->drv->name, GFP_KERNEL); drvname is already treated as optional by phy_reply_size(), phy_fill_reply() and phy_cleanup_data(), so just skip the allocation when there is no driver bound.
A vulnerability in the Linux kernel's handling of Ethernet PHY devices can lead to a NULL pointer dereference. This issue occurs in the net: ethtool: phy component when a PHY driver is unbound, leaving the phy_device still attached to its net_device. The unbinding process removes the driver reference but does not detach the PHY device, causing it to remain in the link topology. When a request is made to retrieve the PHY device information, the absence of a bound driver leads to a crash. This vulnerability affects Linux kernel versions 6.13.x.
Users can upgrade to the latest stable version of the Linux kernel where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/17fe2381f967d353183f374a1c0181a6d194158c | kernel.org | PatchMitigation |
| https://git.kernel.org/stable/c/3586924625559e6f9876d726c80ff0a75f0d5849 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e3adf69f8eb121a9128c2b0029efd050d3649153 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.16, < 6.18.34 >= 6.19, < 7.0.11 7.1 rc1 7.1 rc2 7.1 rc3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 13, 2026 | Initial Analysis | [email protected] |
| Jul 24, 2026 | New CVE Received | kernel.org |