{"id":"CVE-2026-98008","published":"2026-09-25T11:17:29.080","lastModified":"2026-09-25T11:17:29.080","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns early without allocating the MDIO bus,\nleaving bp->mii_bus as NULL.\n\nTwo cleanup paths then dereference this NULL bus:\n\n1. On driver unbind, macb_remove() unconditionally calls\n   mdiobus_unregister(bp->mii_bus), which oopses:\n\n  Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8\n  pc : mdiobus_unregister+0x14/0xa4\n  lr : macb_remove+0x38/0xa4\n  Call trace:\n   mdiobus_unregister+0x14/0xa4 (P)\n   macb_remove+0x38/0xa4\n   platform_remove+0x20/0x30\n   device_release_driver_internal+0x1c8/0x224\n   unbind_store+0xb4/0xbc\n\n2. On the probe error path in macb_probe(), reached when\n   macb_mii_init() has succeeded but a subsequent step fails, the\n   err_out_unregister_mdio label runs the same unconditional cleanup.\n\nmdiobus_unregister() and mdiobus_free() do not guard against a NULL\nbus, so guard the calls in both macb_remove() and the probe error\npath.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a","tags":[]},{"url":"https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4","tags":[]},{"url":"https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3","tags":[]},{"url":"https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}