Impact
In the Linux kernel’s net: phylink subsystem, the function phylink_inband_caps() incorrectly validates the PCS pointer returned by mac_select_pcs. The code only checks for a NULL value, while mac_select_pcs can also return an error pointer. As a result, phylink_pcs_inband_caps() may dereference a NULL or error pointer, causing a kernel panic. This flaw falls under CWE-476 – dereference of a null pointer. The immediate consequence of an exploited flaw is a system crash, stopping all kernel operations until a reboot is performed.
Affected Systems
All Linux kernel versions prior to the patch that implements correct error‑pointer validation are affected. No specific version range is listed, so any older release that has not yet incorporated the fix is vulnerable. The affected product is the Linux kernel itself, as indicated by the vendor/product name Linux kernel.
Risk and Exploitability
The CVSS score of 4.1 indicates a low‑to‑moderate severity, and the EPSS score is below 1%, showing that exploitation is unlikely. The flaw is not listed in CISA KEV, so it is not a known actively exploited vulnerability. Based on the description, the attack vector is inferred to be a local or privileged kernel execution scenario—an attacker must gain the ability to trigger the code path that calls phylink_inband_caps() from kernel context. Even though the vulnerability can crash the system, it does not provide an obvious remote code execution path.
OpenCVE Enrichment