CVE-2026-97963
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net: stmmac: initialize ptp_lock at probe time
priv->ptp_lock is only initialized in stmmac_ptp_register(), which runs during __stmmac_open(). However, the lock is also used while the interface is down and has never been opened: tc_taprio_configure() invokes the PTP gettime64() callback to compute the EST base time when offloading a TAPRIO schedule, and stmmac_get_time() takes priv->ptp_lock. Using an uninitialized rwlock is undefined behaviour. Move the rwlock_init() to __stmmac_dvr_probe(), together with the other private locks, so that ptp_lock is always valid regardless of the interface state.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | b60189e0392fa06348911077ef281eb2b1047b6a < 420315413b29635de1d4ea4142e410e6465260f3 | affected |
| Linux | Linux | b60189e0392fa06348911077ef281eb2b1047b6a < 25cc0096efba83b4e0e6fa50f03e9543b41e9d3d | affected |
| Linux | Linux | b60189e0392fa06348911077ef281eb2b1047b6a < b1986595cf827c38ff929e22fbc9ca8f76379306 | affected |
| Linux | Linux | b60189e0392fa06348911077ef281eb2b1047b6a < 0338c68e22abd2ee509ec2e32508a50896618c32 | affected |
| Linux | Linux | 5.6 | affected |
| Linux | Linux | 0 < 5.6 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/420315413b29635de1d4ea4142e410e6465260f3
- https://git.kernel.org/stable/c/25cc0096efba83b4e0e6fa50f03e9543b41e9d3d
- https://git.kernel.org/stable/c/b1986595cf827c38ff929e22fbc9ca8f76379306
- https://git.kernel.org/stable/c/0338c68e22abd2ee509ec2e32508a50896618c32
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.