Junglewise Threat Intelligence

CVE-2026-64228: Linux Kernel NULL dereference in ethtool PHY driver unbinding

CVE-2026-64228 · Severity: info · Published 2026-07-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to cause a system crash. The issue occurs when certain hardware drivers for network physical layers (PHY) are disconnected or 'unbound' while the system is running. If a management tool then tries to query the status of that hardware, the system may encounter a fatal error (kernel oops), potentially leading to a service outage or system instability.

Technical details

A NULL pointer dereference exists in net/ethtool/phy.c within the Linux kernel. The vulnerability is triggered when a PHY driver is unbound via sysfs (e.g., via /sys/bus/mdio_bus/drivers/.../unbind), which clears the phydev->drv pointer but leaves the device in the link topology xarray. Subsequent calls to ETHTOOL_MSG_PHY_GET invoke phy_prepare_data(), which attempts to access phydev->drv->name without a NULL check, resulting in a kernel oops. The fix introduces a check to ensure the driver pointer is valid before attempting to copy the driver name. This issue affects kernels from version 6.16 onwards and has been patched in stable releases 6.18.34, 7.0.11, and 7.1.

Affected products

  • Linux Linux 6.16 to 6.18.33, 7.0.10

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References