net: phy: micrel: always set shared->phydev for LAN8814
Published Dec 4, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.20%
Description
Currently, during the LAN8814 PTP probe shared->phydev is only set if PTP clock gets actually set, otherwise the function will return before setting it.
This is an issue as shared->phydev is unconditionally being used when IRQ is being handled, especially in lan8814_gpio_process_cap and since it was not set it will cause a NULL pointer exception and crash the kernel.
So, simply always set shared->phydev to avoid the NULL pointer exception.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.10StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.10
- Version 6.12.56StatusunaffectedConstraints<=6.12.*
- Version 6.17.6StatusunaffectedConstraints<=6.17.*
- Version 6.18StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The change hardens the LAN8814 PTP probe path by always initializing shared->phydev so that IRQ handlers cannot dereference NULL if PTP clock registration fails. Impact is limited to systems with the LAN8814 PHY and results in a local kernel crash (DoS).
No CWE recorded.
References (8)
- https://access.redhat.com/security/cve/CVE-2025-40239 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418827 Issue Tracking
- https://git.kernel.org/stable/c/399d10934740ae8cdaa4e3245f7c5f6c332da844
- https://git.kernel.org/stable/c/b093b06826b836c2824858669db080c190c04715
- https://git.kernel.org/stable/c/da1ef8e9eb5d4a12bec32d11636e521e7d529b9e
- https://lore.kernel.org/linux-cve-announce/2025120402-CVE-2025-40239-beb9@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-40239
- https://www.cve.org/CVERecord?id=CVE-2025-40239
Change history (0)
No recorded changes yet.