Executive brief
The Linux kernel's phylink networking subsystem contains a flaw in how it validates the return value of a MAC select function. When the function returns an error pointer instead of NULL, the kernel attempts to dereference invalid memory, causing a system crash (kernel panic). This affects systems using certain network interface drivers that rely on phylink for link management.
Technical details
A validation flaw exists in the phylink_inband_caps() function in drivers/net/phy/phylink.c. The function calls mac_select_pcs() and checks only whether the returned pointer is NULL, but the function can also return an error pointer (ERR_PTR). The code then passes this error pointer to phylink_pcs_inband_caps(), which directly dereferences the ops field without null/error checking, leading to a kernel panic. The fix replaces the NULL check (!pcs) with IS_ERR_OR_NULL(pcs) to handle both NULL and error pointers. This is a local denial-of-service condition requiring the ability to trigger phylink_inband_caps() code path, typically through network driver initialization or configuration changes.
Affected products
- Linux Linux kernel Multiple versions (see git stable tree references)
Timeline
- 2026-09-11: disclosed
- 2026-08-20: patched