Description
In the Linux kernel, the following vulnerability has been resolved:

net: dsa: sja1105: round up PTP perout pin duration

pin_duration is converted from the user-provided period to SJA1105
clock ticks and is later passed as the cycle_time argument to
future_base_time().

Very small period values may become zero after the conversion,
which can lead to a division by zero in future_base_time().

Round zero pin_duration up to 1 tick so that the smallest unsupported
periods use the minimum non-zero hardware duration instead of passing
zero to future_base_time().
Published: 2026-08-15
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises when the Linux kernel converts a user‑provided period to hardware ticks for the SJA1105 PTP driver; very small period values can round down to zero, causing a division by zero in the future_base_time() function. This can crash the kernel or the PTP subsystem, resulting in a loss of network timing services and a possible denial of service.

Affected Systems

The affected component is the Linux kernel's SJA1105 driver, which is part of the DSA (Data Switch Architecture) subsystem. The vulnerability applies to any kernel version that contains the driver code before the round‑up fix has been applied; specific version information is not provided.

Risk and Exploitability

Because the flaw requires the attacker to supply a period value that the driver interprets, the likely attack vector is local or via privileged manipulation of network device configuration. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation. No public exploits are documented, and the absence of KEV listing does not diminish the potential impact of a kernel crash. The vulnerability can lead to service interruption, and the lack of exploitation data suggests moderate to high risk for affected systems.

Generated by OpenCVE AI on August 22, 2026 at 03:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Linux kernel to a release that incorporates the fix shown in the referenced commits.
  • If an immediate kernel upgrade is not possible, disable the SJA1105 driver or turn off PTP per‑output pin functionality on devices that do not require it.
  • Reboot the system to load the updated driver.

Generated by OpenCVE AI on August 22, 2026 at 03:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 15 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: dsa: sja1105: round up PTP perout pin duration pin_duration is converted from the user-provided period to SJA1105 clock ticks and is later passed as the cycle_time argument to future_base_time(). Very small period values may become zero after the conversion, which can lead to a division by zero in future_base_time(). Round zero pin_duration up to 1 tick so that the smallest unsupported periods use the minimum non-zero hardware duration instead of passing zero to future_base_time().
Title net: dsa: sja1105: round up PTP perout pin duration
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:14:12.457Z

Reserved: 2026-08-09T03:40:39.927Z

Link: CVE-2026-72414

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:15.003

Modified: 2026-08-17T06:19:08.267

Link: CVE-2026-72414

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72414 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T03:45:03Z

Weaknesses