Junglewise Threat Intelligence

CVE-2026-45874: Linux Kernel NULL pointer dereference in Freescale imx8qm-hsio PHY driver

CVE-2026-45874 · Severity: info · CVSS 5.5 · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Freescale i.MX8QM HSIO PHY driver could allow a local user to cause a system crash. This occurs when specific hardware configuration properties are missing, leading to a kernel panic. While it does not directly expose data, it can impact the availability of systems using this specific hardware.

Technical details

A NULL pointer dereference exists in the imx_hsio_configure_clk_pad() function within drivers/phy/freescale/phy-fsl-imx8qm-hsio.c. During the driver probe process, the 'refclk_pad' pointer is initialized to NULL if the 'fsl,refclk-pad-mode' property is absent from the devicetree. The driver subsequently attempts to use this pointer in a strncmp operation without a NULL check, leading to a kernel panic. This is a local vulnerability requiring the ability to trigger driver initialization or configuration with a specific devicetree state. Patches have been merged into multiple stable kernel branches.

Affected products

  • Linux Linux Kernel i.MX8QM HSIO PHY driver

Timeline

  • 2026-01-14: other: Patch authored
  • 2026-05-27: advisory: CVE published

References

Related threats