In the Linux kernel, the following vulnerability has been resolved: net: phy: don't try to setup PHY-driven SFP cages when using genphy We don't… (CVE-2026-53231)
In the Linux kernel, the following vulnerability has been resolved: net: phy: don't try to setup PHY-driven SFP cages when using genphy We don't have support for PHY-driver SFP cages with the genphy code. On top of that, it was found by sashiko that running sfp_bus_add_upstream() for genphy deadlocks, as for genphy the PHY probing runs under RTNL, which isn't the case for non-genphy drivers. This problem was reproduced, and does lead to a deadlock on RTNL. Before the blamed commit, the phy_sfp_probe() call was made by individual PHY drivers, so there was no way to get to the SFP probing path when using genphy. Let's therefore only run phy_sfp_probe when not using genphy.
AI Analysis
Technical Summary
The Linux kernel had a vulnerability where the network PHY driver attempted to set up PHY-driven SFP cages when using the generic PHY (genphy) code, which lacks support for such cages. Specifically, calling sfp_bus_add_upstream() for genphy results in a deadlock because genphy PHY probing occurs under the RTNL lock, unlike non-genphy drivers. This deadlock was reproducible and caused a denial of service condition. The fix involved modifying the code to only run phy_sfp_probe when not using genphy, preventing the deadlock scenario.
Potential Impact
The vulnerability causes a deadlock in the Linux kernel's network PHY subsystem, leading to a denial of service (DoS) condition. There is no confidentiality or integrity impact reported. The attack vector requires local access with low privileges and no user interaction is needed. The vulnerability affects system availability by halting network-related kernel operations under RTNL lock.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix involves changes to the Linux kernel source to avoid running phy_sfp_probe for genphy drivers, preventing the deadlock. Users should monitor official Linux kernel updates and apply patches when available.
In the Linux kernel, the following vulnerability has been resolved: net: phy: don't try to setup PHY-driven SFP cages when using genphy We don't… (CVE-2026-53231)
Description
In the Linux kernel, the following vulnerability has been resolved: net: phy: don't try to setup PHY-driven SFP cages when using genphy We don't have support for PHY-driver SFP cages with the genphy code. On top of that, it was found by sashiko that running sfp_bus_add_upstream() for genphy deadlocks, as for genphy the PHY probing runs under RTNL, which isn't the case for non-genphy drivers. This problem was reproduced, and does lead to a deadlock on RTNL. Before the blamed commit, the phy_sfp_probe() call was made by individual PHY drivers, so there was no way to get to the SFP probing path when using genphy. Let's therefore only run phy_sfp_probe when not using genphy.
CVSS v3.1
Score 5.5medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel had a vulnerability where the network PHY driver attempted to set up PHY-driven SFP cages when using the generic PHY (genphy) code, which lacks support for such cages. Specifically, calling sfp_bus_add_upstream() for genphy results in a deadlock because genphy PHY probing occurs under the RTNL lock, unlike non-genphy drivers. This deadlock was reproducible and caused a denial of service condition. The fix involved modifying the code to only run phy_sfp_probe when not using genphy, preventing the deadlock scenario.
Potential Impact
The vulnerability causes a deadlock in the Linux kernel's network PHY subsystem, leading to a denial of service (DoS) condition. There is no confidentiality or integrity impact reported. The attack vector requires local access with low privileges and no user interaction is needed. The vulnerability affects system availability by halting network-related kernel operations under RTNL lock.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. The fix involves changes to the Linux kernel source to avoid running phy_sfp_probe for genphy drivers, preventing the deadlock. Users should monitor official Linux kernel updates and apply patches when available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cmgx-qw5m-5j29
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-53231"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a46eca827e9c7971943a5e7
Added to database: 07/02/2026, 22:56:40 UTC
Last enriched: 07/02/2026, 23:01:19 UTC
Last updated: 07/31/2026, 19:24:46 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.