CVE-2026-68133

Summary

In the Linux kernel, the following vulnerability has been resolved:

ice: fix PTP Call Trace during PTP release

If a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then ice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will result in the following PTP release call trace during driver unload:

kernel BUG at lib/list_debug.c:52!
ice_ptp_release+0x332/0x3c0 [ice]
ice_deinit_features.part.0+0x10e/0x120 [ice]
ice_remove+0x100/0x220 [ice]

This was observed when passing PF1 through to a VM. ice_ptp_init() fails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.

Fix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and returning without error, preventing the invalid state transition to ICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from ICE_PTP_RESETTING after a failed rebuild.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 < 7d517b255f669cedd09830214d55f2f413b34481affected
LinuxLinux8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 < e4406cbdd915f702d2ed9ee8b30683a16b06c6acaffected
LinuxLinux8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 < 14fceda28069fdbe1bb49cdb6e1774892b583348affected
LinuxLinux8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 < f6a7e00b81e35ef1325234925f2fe1e53b466f92affected
LinuxLinux6.9affected
LinuxLinux0 < 6.9unaffected
LinuxLinux6.12.101 <= 6.12.*unaffected
LinuxLinux6.18.42 <= 6.18.*unaffected
LinuxLinux7.1.6 <= 7.1.*unaffected
LinuxLinux7.2-rc5 <= *unaffected

Weaknesses

References