Description
In the Linux kernel, the following vulnerability has been resolved:

net: phylink: correctly validate returned PCS in phylink_inband_caps

In phylink_inband_caps(), the PCS returned by mac_select_pcs is only
checked if NULL but mac_select_pcs can also return an error pointer.

This can cause a kernel panic as phylink_pcs_inband_caps() only checks
if passed PCS is not NULL and directly dereference ops from the phylink_pcs
struct.

Use the IS_ERR_OR_NULL macro to address both case where the returned
PCS can be NULL or an error pointer and prevent a kernel panic.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (Kernel Panic)
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s net: phylink subsystem, the function phylink_inband_caps() incorrectly validates the PCS pointer returned by mac_select_pcs. The code only checks for a NULL value, while mac_select_pcs can also return an error pointer. As a result, phylink_pcs_inband_caps() may dereference a NULL or error pointer, causing a kernel panic. This flaw falls under CWE-476 – dereference of a null pointer. The immediate consequence of an exploited flaw is a system crash, stopping all kernel operations until a reboot is performed.

Affected Systems

All Linux kernel versions prior to the patch that implements correct error‑pointer validation are affected. No specific version range is listed, so any older release that has not yet incorporated the fix is vulnerable. The affected product is the Linux kernel itself, as indicated by the vendor/product name Linux kernel.

Risk and Exploitability

The CVSS score of 4.1 indicates a low‑to‑moderate severity, and the EPSS score is below 1%, showing that exploitation is unlikely. The flaw is not listed in CISA KEV, so it is not a known actively exploited vulnerability. Based on the description, the attack vector is inferred to be a local or privileged kernel execution scenario—an attacker must gain the ability to trigger the code path that calls phylink_inband_caps() from kernel context. Even though the vulnerability can crash the system, it does not provide an obvious remote code execution path.

Generated by OpenCVE AI on September 21, 2026 at 02:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the proper phylink_inband_caps() validation fix.
  • If the patch is not yet available, disable or constrain phylink functionality that triggers the vulnerable code path through kernel configuration or network settings to avoid execution of phylink_inband_caps().
  • Enable a watchdog or automated reboot service to recover from unexpected kernel panics, minimizing downtime while a patch or configuration change is applied.

Generated by OpenCVE AI on September 21, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: phylink: correctly validate returned PCS in phylink_inband_caps In phylink_inband_caps(), the PCS returned by mac_select_pcs is only checked if NULL but mac_select_pcs can also return an error pointer. This can cause a kernel panic as phylink_pcs_inband_caps() only checks if passed PCS is not NULL and directly dereference ops from the phylink_pcs struct. Use the IS_ERR_OR_NULL macro to address both case where the returned PCS can be NULL or an error pointer and prevent a kernel panic.
Title net: phylink: correctly validate returned PCS in phylink_inband_caps
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-11T19:42:49.521Z

Reserved: 2026-08-26T14:34:25.812Z

Link: CVE-2026-80993

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:06.237

Modified: 2026-09-11T20:19:06.237

Link: CVE-2026-80993

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:49Z

Links: CVE-2026-80993 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses