-
CVE-2026-90100
- EPSS 0.2%
- Veröffentlicht 17.09.2026 16:06:11
- Zuletzt bearbeitet 17.09.2026 17:17:01
- Erkennungen
ptp: netc: fix period truncation and potential divide-by-zero in PEROUT
In the Linux kernel, the following vulnerability has been resolved:
ptp: netc: fix period truncation and potential divide-by-zero in PEROUT
The max_period bound in net_timer_enable_perout() was computed as:
max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period;
which exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for
the default 333333333 Hz clock). A period_ns that passes this check but
exceeds U32_MAX is then silently truncated when stored into the u32
struct netc_pp::period field.
A truncated value of zero can reach netc_timer_set_perout_alarm(), where
the local u32 period variable would also be 0, causing a divide-by-zero
in roundup_u64(delta, period) whenever the stime < min_time branch is
taken (which always happens for a start time of {0, 0}).
Additionally, netc_timer_enable_periodic_pulse() and
netc_timer_enable_fiper() both compute:
fiper = pp->period - integral_period;
A zero pp->period results in an unsigned wraparound to 0xFFFFFFFD,
mis-programming the FIPER hardware register.
Fix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER
(0xFFFFFFFF). This ensures that any period_ns passing the range check
fits in a u32 without truncation, so the stored value is always valid
and non-zero. The accepted range is reduced by integral_period ns
(typically only a few nanoseconds), which is negligible in practice.Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
671e266835b8a87d6cc2c6db962de23783405dd8
Version <
51fe3fe0ffec033bd831c71d9bee3dee827e491c
Status
affected
Version
671e266835b8a87d6cc2c6db962de23783405dd8
Version <
08988d1941e180f0ad30d91233cb64f3418ba23c
Status
affected
Version
671e266835b8a87d6cc2c6db962de23783405dd8
Version <
777dbc9914b2f003f1d44af80c7a4a395c5961b2
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.18
Status
affected
Version
0
Version <
6.18
Status
unaffected
Version <=
6.18.*
Version
6.18.52
Status
unaffected
Version <=
7.2.*
Version
7.2.6
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
https://git.kernel.org/stable/c/51fe3fe0ffec033bd831c71d9bee3dee827e491c
https://git.kernel.org/stable/c/08988d1941e180f0ad30d91233cb64f3418ba23c
https://git.kernel.org/stable/c/777dbc9914b2f003f1d44af80c7a4a395c5961b2