SB2025092374 - NULL pointer dereference in Linux kernel ethernet freescale driver
Published: September 23, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-39876)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the fec_enet_phy_reset_after_clk_enable() function in drivers/net/ethernet/freescale/fec_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/03e79de4608bdd48ad6eec272e196124cefaf798
- https://git.kernel.org/stable/c/4fe53aaa4271a72fe5fe3e88a45ce01646b68dc5
- https://git.kernel.org/stable/c/5f1bb554a131e59b28482abad21f691390651752
- https://git.kernel.org/stable/c/eb148d85e126c47d65be34f2a465d69432ca5541
- https://git.kernel.org/stable/c/fe78891f296ac05bf4e5295c9829ef822f3c32e7