PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64228 Linux CVE debrief

A vulnerability was found in the Linux kernel's network ethtool phy functionality. When a PHY driver is unbound, the phydev->drv can become NULL while the phy_device remains attached to its net_device. This can cause a NULL dereference when ETHTOOL_MSG_PHY_GET is called. The issue arises from phy_remove() clearing phydev->drv without calling phy_detach().

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-24
Original CVE updated
2026-08-13
Advisory published
2026-07-24
Advisory updated
2026-08-13

Who should care

Linux kernel maintainers, Linux distribution vendors, and users of Linux kernel versions 6.16 to 6.18.34, 6.19 to 7.0.11, and specific release candidates for version 7.1 should be aware of this vulnerability. They should assess their exposure, apply patches, and monitor for similar issues in the future. Security teams and operators managing Linux-based systems should prioritize patching and review compensating controls for exposed systems. Vulnerability management processes should include checks for this class of issue in kernel updates and driver management practices. System administrators should ensure that they are using supported kernel versions and have a plan for applying patches and mitigating potential impacts. Additionally, defenders should verify system configurations, monitor for suspicious activity, and maintain an inventory of affected systems to ensure timely remediation. IT and security teams should coordinate on patch deployment and verify the effectiveness of compensating controls where patches cannot be immediately applied. Asset owners should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. This should involve reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review, and exceptions, retested remediated assets, should be tracked, and the item only closed after evidence is documented. This process should be part of a broader vulnerability management program that includes regular reviews of kernel and driver updates, as well as assessments of operational impact and source-confidence limits. By taking these steps, organizations can reduce their risk exposure and improve their overall security posture regarding this vulnerability in the Linux kernel's network ethtool phy functionality. Linux distributions and vendors should also

Technical summary

The vulnerability occurs in the Linux kernel's network ethtool phy functionality. When a PHY driver is unbound via sysfs, phydev->drv can become NULL while the phy_device remains attached to its net_device. This leads to a NULL dereference in ETHTOOL_MSG_PHY_GET when trying to access phydev->drv->name. The issue arises because phy_remove() clears phydev->drv without calling phy_detach(). Affected users should be cautious with PHY driver unbinding and consider updating to patched kernel versions.

Defensive priority

Medium priority due to potential local denial of service

Recommended defensive actions

  • Apply patches from Linux kernel stable branches
  • Unbind PHY drivers with caution
  • Monitor for similar NULL pointer dereferences
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE record and NVD details were analyzed. The vulnerability allows for a local denial of service attack. Affected versions include Linux kernel versions 6.16 to 6.18.34, 6.19 to 7.0.11, and specific release candidates for version 7.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64228 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64228

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64228 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64228

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/17fe2381f967d353183f374a1c0181a6d194158c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch, Mitigation

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/3586924625559e6f9876d726c80ff0a75f0d5849

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e3adf69f8eb121a9128c2b0029efd050d3649153

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.