5.5

CVE-2026-31727

usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo

In the Linux kernel, the following vulnerability has been resolved:

usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo

Commit ec35c1969650 ("usb: gadget: f_ncm: Fix net_device lifecycle with
device_move") reparents the gadget device to /sys/devices/virtual during
unbind, clearing the gadget pointer. If the userspace tool queries on
the surviving interface during this detached window, this leads to a
NULL pointer dereference.

Unable to handle kernel NULL pointer dereference
Call trace:
 eth_get_drvinfo+0x50/0x90
 ethtool_get_drvinfo+0x5c/0x1f0
 __dev_ethtool+0xaec/0x1fe0
 dev_ethtool+0x134/0x2e0
 dev_ioctl+0x338/0x560

Add a NULL check for dev->gadget in eth_get_drvinfo(). When detached,
skip copying the fw_version and bus_info strings, which is natively
handled by ethtool_get_drvinfo for empty strings.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 6.12.78 < 6.12.81
Linux ≫ Linux Kernel Version >= 6.18.19 < 6.18.22
Linux ≫ Linux Kernel Version >= 6.19.9 < 6.19.12
Linux ≫ Linux Kernel Version 7.0 Update rc1
Linux ≫ Linux Kernel Version 7.0 Update rc2
Linux ≫ Linux Kernel Version 7.0 Update rc3
Linux ≫ Linux Kernel Version 7.0 Update rc4
Linux ≫ Linux Kernel Version 7.0 Update rc5
Linux ≫ Linux Kernel Version 7.0 Update rc6
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.024
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/0326429e8ba99892e1d1e115dc8e88e1a3b64e24
Patch
https://git.kernel.org/stable/c/a36e5e800b9c93e3e1ffa42f34d38b36775dbcee
Patch
https://git.kernel.org/stable/c/7de4d46be40738c7e48e64b5cc0a34aa1e047b0a
Patch
https://git.kernel.org/stable/c/e002e92e88e12457373ed096b18716d97e7bbb20
Patch