In the Linux kernel, the following vulnerability has been resolved:
net: ethtool: netlink: Allow NULL nlattrs when getting a phy_device
ethnl_req_get_phydev() is used to lookup a phy_device, in the case an ethtool netlink command targets a specific phydev within a netdev's topology.
It takes as a parameter a const struct nlattr *header that's used for error handling :
if (!phydev) { NL_SET_ERR_MSG_ATTR(extack, header, "no phy matching phyindex"); return ERR_PTR(-ENODEV); }
In the notify path after a ->set operation however, there's no request attributes available.
The typical callsite for the above function looks like:
phydev = ethnl_req_get_phydev(req_base, tb[ETHTOOL_A_XXX_HEADER], info->extack);
So, when tb is NULL (such as in the ethnl notify path), we have a nice crash.
It turns out that there's only the PLCA command that is in that case, as the other phydev-specific commands don't have a notification.
This commit fixes the crash by passing the cmd index and the nlattr array separately, allowing NULL-checking it directly inside the helper.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 1, 2025 |
| Suse | — | Upgrade kernel-default-livepatchUpgrade kernel-develUpgrade kernel-64kbUpgrade kernel-docs-htmlUpgrade kernel-symsUpgrade kernel-kvmsmallUpgrade kernel-devel-azureUpgrade kernel-source-vanillaUpgrade kernel-default-develUpgrade kernel-zfcpdumpUpgrade kernel-kvmsmall-develUpgrade kernel-default-vdsoUpgrade kernel-kvmsmall-vdsoUpgrade kernel-source-azureUpgrade kernel-azure-extraUpgrade kernel-azureUpgrade kernel-sourceUpgrade kernel-default-extraUpgrade kernel-defaultUpgrade kernel-64kb-develUpgrade kernel-azure-develUpgrade kernel-macrosUpgrade kernel-docsUpgrade kernel-obs-qaUpgrade kernel-azure-vdsoUpgrade kernel-64kb-extra | Dec 5, 2025 | Dec 5, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub