Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix NULL pointer dereference in phy_reply_size In phy_prepare_data(), several strings such as 'name', 'drvname', 'upstream_sfp_name', and 'downstream_sfp_name' are allocated using kstrdup(). However, these allocations were not checked for failure. If kstrdup() fails for 'name', it returns NULL while the function continues. This leads to a kernel NULL pointer dereference and panic later in phy_reply_size() when it unconditionally calls strlen() on the NULL pointer. While other strings like 'upstream_sfp_name' might be checked before access in certain code paths, failing to handle these allocations consistently can lead to incomplete data reporting or hidden bugs. Fix this by adding proper NULL checks for all kstrdup() calls in phy_prepare_data() and implement a centralized error handling path using goto labels to ensure all previously allocated resources are freed on failure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.16, < 6.18.34 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/3dbe20a3809347bacda890822e7ca013bd85a18cPatch
- https://git.kernel.org/stable/c/4908f1395fb1b832ceec11584af649874a2732eaPatch
- https://git.kernel.org/stable/c/61f53c1e58d68723bc1db10912a53f1991f08719Patch
FAQ
What is CVE-2026-64120?
CVE-2026-64120 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: net: ethtool: fix NULL pointer dereference in phy_reply_size In phy_prepare_data(), several strings such as 'name', 'drvname', 'up...
How severe is CVE-2026-64120?
CVE-2026-64120 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-64120?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.