Description
In the Linux kernel, the following vulnerability has been resolved:

net: ravb: serialize PTP clock teardown

ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to
ptp_clock_event() while ptp_clock_unregister() is freeing it. This can
lead to a use-after-free.

Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.
Atomically detach it with xchg() before disabling PTP interrupts, then
synchronize all IRQs which can invoke ravb_ptp_interrupt() before
unregistering the detached clock.

A handler which read the old pointer completes before the clock is
unregistered, while later handlers read NULL and skip the event.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Use‑after‑free in Linux kernel PTP clock teardown
Action: Apply Patch Immediately
AI Analysis

Impact

The flaw is a race condition (CWE‑364) between ravb_ptp_interrupt() and ravb_ptp_stop() that results in a use‑after‑free of the PTP clock object. Once the clock can still dereference the pointer, leading to memory corruption and kernel crashes, impacting kernel integrity andThe CVSS score is 7.8, indicating a high-level severity. The EPSS score is below 1%, showing a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The use‑after‑free could be exploited by a local or privileged user who can trigger the relevant interrupts, but no public exploits are documented.

Affected Systems

The vulnerability is present in Linux kernel builds that contain the ravb networking driver before the patch that serializes the PTP clock teardown. No specific affected‑version range is listed, so any kernel incorporating that code path could be at risk.

Risk and Exploitability

The CVSS score of 7.8 classifies this flaw as high severity, while the EPSS score below 1% suggests a low probability of exploitation. Because the flaw is a local use‑after‑free race condition, a privileged or local attacker who can trigger PTP interrupts during teardown could potentially crash the kernel or, in a worst‑case scenario, achieve privilege escalation. The vulnerability is not part of the CISA KEV catalog, so there are currently no publicly reported or weaponized exploits.

Generated by OpenCVE AI on September 21, 2026 at 01:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the fix for the ravb PTP clock teardown race condition.
  • Restart the system or reload the affected module to ensure the updated code is active.
  • If PTP functionality is unnecessary, disable the ravb driver or PTP support to eliminate the fault path.

Generated by OpenCVE AI on September 21, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-364
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to ptp_clock_event() while ptp_clock_unregister() is freeing it. This can lead to a use-after-free. Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer. Atomically detach it with xchg() before disabling PTP interrupts, then synchronize all IRQs which can invoke ravb_ptp_interrupt() before unregistering the detached clock. A handler which read the old pointer completes before the clock is unregistered, while later handlers read NULL and skip the event.
Title net: ravb: serialize PTP clock teardown
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-13T06:28:55.151Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80991

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.993

Modified: 2026-09-13T07:17:05.830

Link: CVE-2026-80991

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:48Z

Links: CVE-2026-80991 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:00:09Z

Weaknesses
  • CWE-364

    Signal Handler Race Condition