Executive brief
The Linux kernel's Ethernet MAC (EMAC) driver is used to manage network connectivity on embedded systems. A race condition during device initialization allows an interrupt handler to be invoked before the driver's memory registers are properly mapped, causing a kernel crash that could be exploited to trigger a denial of service.
Technical details
This is a NULL pointer dereference vulnerability in the IBM EMAC network driver initialization routine (emac_probe). The root cause is an ordering issue: the interrupt handler registration (devm_request_irq) was occurring before the memory-mapped I/O register region (emacp) was initialized via devm_platform_ioremap_resource. If an early interrupt fires during the probe phase, the handler (emac_irq) attempts to dereference the NULL emacp pointer, causing a kernel panic. The fix reorders these operations so that the I/O region is mapped before the IRQ handler is registered. No preconditions beyond device presence are required; the vulnerability is triggered by timing of hardware interrupt delivery. The patch is available in upstream Linux and stable backports.
Affected products
- Linux Linux kernel Multiple versions prior to patch (affects EMAC driver in drivers/net/ethernet/ibm/emac)
Timeline
- 2026-08-28: disclosed
- 2026-07-24: patched: Fix committed upstream and backported to stable kernel branches