{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80614","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.773Z","datePublished":"2026-08-28T06:48:35.720Z","dateUpdated":"2026-08-29T06:21:22.838Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-29T06:21:22.838Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: emac: Fix NULL pointer dereference in emac_probe\n\nMove devm_request_irq() after devm_platform_ioremap_resource() so that\ndev->emacp is mapped before the interrupt handler can fire.  An early\ninterrupt hitting emac_irq() would dereference the NULL dev->emacp and\ncrash.\n\nAlso remove redundant error message. devm_platform_ioremap_resource()\nalready returns an error message with dev_err_probe()."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - IBM EMAC error IRQs are raised by the on-chip Ethernet controller from wire-side events; a remote attacker on the attached network can send Ethernet traffic during emac_probe to assert interrupts that invoke emac_irq() before dev->emacp is ioremap'd.\nAC:L - Once devm_request_irq() registers emac_irq(), any EMAC interrupt fires immediately; an attacker can sustain Ethernet flooding throughout boot/probe, and firmware often leaves the controller active with pending IRQs that hit the narrow pre-ioremap window reliably.\nPR:N - Triggering EMAC hardware interrupts requires only the ability to send Ethernet frames on the connected network segment during driver probe, not local shell access, capabilities, or authenticated sessions.\nUI:N - Exploitation occurs during automatic platform-driver probe at kernel boot or module initialization; no discretionary user action is required beyond the device powering on with its Ethernet port connected.\nS:U - A NULL pointer dereference in the EMAC hard-IRQ handler causes a local kernel oops or panic only; it does not cross VM, container, or IOMMU security boundaries.\nC:N - The bug dereferences a NULL dev->emacp when reading ISR registers via in_be32(), causing an immediate kernel fault with no attacker-controlled memory disclosure or out-of-bounds read.\nI:N - Impact is limited to a NULL pointer fault in hardirq context; there is no heap corruption, arbitrary write, or control-flow hijack primitive beyond the crash itself.\nA:H - A NULL pointer dereference in emac_irq() hard interrupt context causes a kernel oops or panic, rendering the entire system unavailable on affected PowerPC embedded platforms."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/ibm/emac/core.c"],"versions":[{"version":"dcc34ef7c83473222027f475014a2bf8ab798372","lessThan":"a103cdb0681e7185d1b0a12ce6a7c5416c208ccd","status":"affected","versionType":"git"},{"version":"dcc34ef7c83473222027f475014a2bf8ab798372","lessThan":"44068b6863fbda78fc810921ddf61642c377b3ca","status":"affected","versionType":"git"},{"version":"dcc34ef7c83473222027f475014a2bf8ab798372","lessThan":"f623d38fe6c4e8c40b23f42cc6fe6963fa49997b","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/ibm/emac/core.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/a103cdb0681e7185d1b0a12ce6a7c5416c208ccd"},{"url":"https://git.kernel.org/stable/c/44068b6863fbda78fc810921ddf61642c377b3ca"},{"url":"https://git.kernel.org/stable/c/f623d38fe6c4e8c40b23f42cc6fe6963fa49997b"}],"title":"net: emac: Fix NULL pointer dereference in emac_probe","x_generator":{"engine":"bippy-1.2.0"}}}}