Home

Description

In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: always set shared->phydev for LAN8814 Currently, during the LAN8814 PTP probe shared->phydev is only set if PTP clock gets actually set, otherwise the function will return before setting it. This is an issue as shared->phydev is unconditionally being used when IRQ is being handled, especially in lan8814_gpio_process_cap and since it was not set it will cause a NULL pointer exception and crash the kernel. So, simply always set shared->phydev to avoid the NULL pointer exception.

PUBLISHED Reserved 2025-04-16 | Published 2025-12-04 | Updated 2025-12-04 | Assigner Linux

Product status

Default status
unaffected

b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 (git) before da1ef8e9eb5d4a12bec32d11636e521e7d529b9e
affected

b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 (git) before b093b06826b836c2824858669db080c190c04715
affected

b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 (git) before 399d10934740ae8cdaa4e3245f7c5f6c332da844
affected

Default status
affected

6.10
affected

Any version before 6.10
unaffected

6.12.56 (semver)
unaffected

6.17.6 (semver)
unaffected

6.18 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/da1ef8e9eb5d4a12bec32d11636e521e7d529b9e

git.kernel.org/...c/b093b06826b836c2824858669db080c190c04715

git.kernel.org/...c/399d10934740ae8cdaa4e3245f7c5f6c332da844

cve.org (CVE-2025-40239)

nvd.nist.gov (CVE-2025-40239)