Impact
The Linux kernel's ena PHC driver incorrectly exposes uninitialized timestamp data through the PTP ioctl interface when the underlying hardware timestamp acquisition fails. The bug causes an information leak and violates correctness by delivering garbage values to userspace.
Affected Systems
The flaw is present in all Linux kernel releases that include the ena driver before the patch, as the vendor list indicates only Linux:Linux. No specific version range is enumerated, so any kernel version using the ena driver is potentially affected until the commit that fixes the issue is deployed.
Risk and Exploitability
CVSS 5.5 reflects moderate risk, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not cataloged in CISA KEV. Exploitation requires a local user or an attack that can invoke the PTP ioctl on the relevant network interface; it does not allow remote code execution or privilege escalation beyond the application already accessing the PTP device.
OpenCVE Enrichment
Ubuntu USN