Description
In the Linux kernel, the following vulnerability has been resolved:

net: ravb: avoid dereferencing an invalid PTP clock

The PTP clock is unavailable before the first open, so querying its
index can dereference a NULL pointer. Registration failures can also
leave an error pointer in priv->ptp.clock.

Cache the PHC index separately and report -1 while no clock is
registered. Normalize registration errors to NULL and preserve the
static timestamping capabilities.
Published: 2026-09-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via kernel crash
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel, the RAVB driver contains a null‑pointer dereference that occurs when the Precision Time Protocol (PTP) clock is queried before it has been opened or after a registration failure. The PTP clock is not yet available, so accessing its index can pointer in the driver structure. The flaw is a classic CWE‑476 vulnerability that can trigger a kernel fault and bring the system down.

Affected Systems

All Linux kernel configurations that compile the RAVB driver are affected. Vendors listed by the CNA are Linux:Linux, meaning any distribution that ships the Linux kernel with the RAVB module compiled is susceptible. This includes the default kernel configuration used by many distributions.

Risk and Exploitability

The CVSS base score of 7.8 denotes high severity. The EPSS probability is reported as less than 1 %, indicating an extremely low likelihood of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. An attacker would typically need local or elevated privileges to interact with the RAVB interface, allowing them to trigger the vulnerability and cause a loss of availability via a crash. Remote exploitation is unlikely without additional local compromise.

Generated by OpenCVE AI on September 21, 2026 at 01:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install a kernel update that includes the RAVB driver fix.
  • If the RAVB driver is not required, disable or unload the module to eliminate vulnerable code.
  • Restrict local access to the RAVB interface by adjusting permissions or using kernel boot parameters to limit use to trusted users.
  • Monitor system logs for unexpected kernel crashes or errors that may indicate attempted exploitation.

Generated by OpenCVE AI on September 21, 2026 at 01:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: ravb: avoid dereferencing an invalid PTP clock The PTP clock is unavailable before the first open, so querying its index can dereference a NULL pointer. Registration failures can also leave an error pointer in priv->ptp.clock. Cache the PHC index separately and report -1 while no clock is registered. Normalize registration errors to NULL and preserve the static timestamping capabilities.
Title net: ravb: avoid dereferencing an invalid PTP clock
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:33.146Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80992

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:06.110

Modified: 2026-09-14T13:18:53.900

Link: CVE-2026-80992

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:48Z

Links: CVE-2026-80992 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:00:09Z

Weaknesses