← All Advisories

CVE-2026-98008

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-98008

Key Details

CVECVE-2026-98008
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: macb: fix NULL pointer dereference on unbind with fixed-link

When the device tree describes a fixed-link and has no "mdio" child

node, macb_mii_init() returns early without allocating the MDIO bus,

leaving bp->mii_bus as NULL.

Two cleanup paths then dereference this NULL bus:

1. On driver unbind, macb_remove() unconditionally calls

mdiobus_unregister(bp->mii_bus), which oopses:

Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8

pc : mdiobus_unregister+0x14/0xa4

lr : macb_remove+0x38/0xa4

Call trace:

mdiobus_unregister+0x14/0xa4 (P)

macb_remove+0x38/0xa4

platform_remove+0x20/0x30

device_release_driver_internal+0x1c8/0x224

unbind_store+0xb4/0xbc

2. On the probe error path in macb_probe(), reached when

macb_mii_init() has succeeded but a subsequent step fails, the

err_out_unregister_mdio label runs the same unconditional cleanup.

mdiobus_unregister() and mdiobus_free() do not guard against a NULL

bus, so guard the calls in both macb_remove() and the probe error

path. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-98008
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-98008