---
id: CVE-2026-98008
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: macb: fix NULL pointer dereference on unbind with fixed-link

  When the device tree describes a fixed-link and has no "mdio" child
  node, macb_mii_init() returns ear…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  net: macb: fix NULL pointer dereference on unbind with fixed-link

  When the device tree describes a fixed-link and has no "mdio" child
  node, macb_mii_init() returns ear…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 <
    f737d999fcb8f276d77b01ea4c2016ee01dad19b
  - >-
    Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 <
    5710f6a74f63cbba0e15cd75917234916181c9d4
  - >-
    Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 <
    edb39c7666bb3924da761dfb417db85c1e5d8ad3
  - >-
    Linux >= d0c3601f2c4e12e7689b0f46ebc17525250ea8c3 <
    38b6be101006d3e7af972999f45d4f1e8250587a
  - Linux cafa5942bd2df3d80e3eeb2deb4bc050f7761f3d
  - Linux c81dcaa9cd0b66816c2ecb6c5df0b6afde9c7da5
  - Linux 831e19e565b5210930fa183730071f8290c61263
  - Linux 81db1e52848694761a1aa162ce76198af9964ed8
  - Linux 19088c5378c9fea54e552d8bc7418a3aa1e06990
  - Linux >= 5.10.228 < 5.11
  - Linux >= 5.15.169 < 5.16
  - Linux >= 6.1.114 < 6.2
  - Linux >= 6.6.58 < 6.7
  - Linux >= 6.11.5 < 6.12
  - Linux 6.12
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:29.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98008'
references:
  - url: 'https://git.kernel.org/stable/c/38b6be101006d3e7af972999f45d4f1e8250587a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5710f6a74f63cbba0e15cd75917234916181c9d4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/edb39c7666bb3924da761dfb417db85c1e5d8ad3'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f737d999fcb8f276d77b01ea4c2016ee01dad19b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.860Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

net: macb: fix NULL pointer dereference on unbind with fixed-link

When the device tree describes a fixed-link and has no "mdio" child
node, macb_mii_init() returns early without allocating the MDIO bus,
leaving bp->mii_bus as NULL.

Two cleanup paths then dereference this NULL bus:

1. On driver unbind, macb_remove() unconditionally calls
   mdiobus_unregister(bp->mii_bus), which oopses:

  Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8
  pc : mdiobus_unregister+0x14/0xa4
  lr : macb_remove+0x38/0xa4
  Call trace:
   mdiobus_unregister+0x14/0xa4 (P)
   macb_remove+0x38/0xa4
   platform_remove+0x20/0x30
   device_release_driver_internal+0x1c8/0x224
   unbind_store+0xb4/0xbc

2. On the probe error path in macb_probe(), reached when
   macb_mii_init() has succeeded but a subsequent step fails, the
   err_out_unregister_mdio label runs the same unconditional cleanup.

mdiobus_unregister() and mdiobus_free() do not guard against a NULL
bus, so guard the calls in both macb_remove() and the probe error
path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
