Impact
The Linux kernel patch adds a missing facility check to the ptp_s390 driver. Without this check, the driver could register a physical clock even when facility 28 is not present, causing the kernel to use a non‑existent time source. This misuse can lead to unstable timing, kernel hangs, or corruption of time‑sensitive processes, representing an availability‑type weakness based on improper input validation.
Affected Systems
The vulnerability exists in the Linux kernel for IBM s390 architecture. Any build that includes the ptp_s390 driver before the patch may be affected; no specific version range is provided.
Risk and Exploitability
EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. With no CVSS score supplied, the exact severity is uncertain. Exploitability appears local, requiring the ability to access the PTP interface on an s390 platform. The lack of public exploit evidence and the absence of a severity score suggest a cautious but uncertain risk level. Attackers with kernel privileges could potentially trigger the misregistered clock, leading to a denial of service.
OpenCVE Enrichment