{"id":"AZL-104673","summary":"CVE-2026-98008 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: macb: fix NULL pointer dereference on unbind with fixed-link\n\nWhen the device tree describes a fixed-link and has no \"mdio\" child\nnode, macb_mii_init() returns early without allocating the MDIO bus,\nleaving bp-\u003emii_bus as NULL.\n\nTwo cleanup paths then dereference this NULL bus:\n\n1. On driver unbind, macb_remove() unconditionally calls\n   mdiobus_unregister(bp-\u003emii_bus), which oopses:\n\n  Unable to handle kernel NULL pointer dereference at virtual address 00000000000004a8\n  pc : mdiobus_unregister+0x14/0xa4\n  lr : macb_remove+0x38/0xa4\n  Call trace:\n   mdiobus_unregister+0x14/0xa4 (P)\n   macb_remove+0x38/0xa4\n   platform_remove+0x20/0x30\n   device_release_driver_internal+0x1c8/0x224\n   unbind_store+0xb4/0xbc\n\n2. On the probe error path in macb_probe(), reached when\n   macb_mii_init() has succeeded but a subsequent step fails, the\n   err_out_unregister_mdio label runs the same unconditional cleanup.\n\nmdiobus_unregister() and mdiobus_free() do not guard against a NULL\nbus, so guard the calls in both macb_remove() and the probe error\npath.","modified":"2026-09-27T05:34:32Z","published":"2026-09-25T11:17:29Z","upstream":["CVE-2026-98008"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98008"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-104673.json"}}],"schema_version":"1.9.0"}