In the Linux kernel, the following vulnerability has been resolved:
net: ethtool: netlink: Allow NULL nlattrs when getting a phy_device
ethnl_req_get_phydev() is used to lookup a phy_device, in the case an ethtool netlink command targets a specific phydev within a netdev's topology.
It takes as a parameter a const struct nlattr *header that's used for error handling :
if (!phydev) { NL_SET_ERR_MSG_ATTR(extack, header, "no phy matching phyindex"); return ERR_PTR(-ENODEV); }
In the notify path after a ->set operation however, there's no request attributes available.
The typical callsite for the above function looks like:
phydev = ethnl_req_get_phydev(req_base, tb[ETHTOOL_A_XXX_HEADER], info->extack);
So, when tb is NULL (such as in the ethnl notify path), we have a nice crash.
It turns out that there's only the PLCA command that is in that case, as the other phydev-specific commands don't have a notification.
This commit fixes the crash by passing the cmd index and the nlattr array separately, allowing NULL-checking it directly inside the helper.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 1, 2025 |
| Suse | — | Upgrade kernel-symsUpgrade kernel-64kbUpgrade kernel-develUpgrade kernel-docs-htmlUpgrade kernel-azure-extraUpgrade kernel-devel-azureUpgrade kernel-kvmsmallUpgrade kernel-default-vdsoUpgrade kernel-kvmsmall-vdsoUpgrade kernel-source-azureUpgrade kernel-sourceUpgrade kernel-source-vanillaUpgrade kernel-default-livepatchUpgrade kernel-default-develUpgrade kernel-azureUpgrade kernel-kvmsmall-develUpgrade kernel-zfcpdumpUpgrade kernel-default-extraUpgrade kernel-defaultUpgrade kernel-azure-vdsoUpgrade kernel-docsUpgrade kernel-64kb-extraUpgrade kernel-64kb-develUpgrade kernel-obs-qaUpgrade kernel-macrosUpgrade kernel-azure-devel | Dec 5, 2025 | Dec 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub