CVE Database
/

CVE-2025-40239

Back to search

CVE-2025-40239

Published: Dec 4, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: always set shared->phydev for LAN8814 Currently, during the LAN8814 PTP probe shared->phydev is only set if PTP clock gets actually set, otherwise the function will return before setting it. This is an issue as shared->phydev is unconditionally being used when IRQ is being handled, especially in lan8814_gpio_process_cap and since it was not set it will cause a NULL pointer exception and crash the kernel. So, simply always set shared->phydev to avoid the NULL pointer exception.

VendorProductVersions

Linux

Linux

affected
b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 - < da1ef8e9eb5d4a12bec32d11636e521e7d529b9e
affected
b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 - < b093b06826b836c2824858669db080c190c04715
affected
b3f1a08fcf0dd58d99b14b9f8fbd1929f188b746 - < 399d10934740ae8cdaa4e3245f7c5f6c332da844

Linux

Linux

affected
6.10
unaffected
0 - < 6.10
unaffected
6.12.56 - <= 6.12.*
unaffected
6.17.6 - <= 6.17.*
unaffected
6.18 - <= *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now