Junglewise Threat Intelligence

CVE-2026-80993: Linux kernel phylink NULL pointer dereference in phylink_inband_caps

CVE-2026-80993 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's phylink networking subsystem contains a flaw in how it validates the return value of a MAC select function. When the function returns an error pointer instead of NULL, the kernel attempts to dereference invalid memory, causing a system crash (kernel panic). This affects systems using certain network interface drivers that rely on phylink for link management.

Technical details

A validation flaw exists in the phylink_inband_caps() function in drivers/net/phy/phylink.c. The function calls mac_select_pcs() and checks only whether the returned pointer is NULL, but the function can also return an error pointer (ERR_PTR). The code then passes this error pointer to phylink_pcs_inband_caps(), which directly dereferences the ops field without null/error checking, leading to a kernel panic. The fix replaces the NULL check (!pcs) with IS_ERR_OR_NULL(pcs) to handle both NULL and error pointers. This is a local denial-of-service condition requiring the ability to trigger phylink_inband_caps() code path, typically through network driver initialization or configuration changes.

Affected products

  • Linux Linux kernel Multiple versions (see git stable tree references)

Timeline

  • 2026-09-11: disclosed
  • 2026-08-20: patched

References

Related threats