Impact
The Linux kernel FEC driver contains a flaw where fec_ptp_stop() is called without confirming that the PTP clock was initialized. This absence of a guard causes the driver to attempt stopping a PTP clock that was never started, potentially leading to a kernel fault or erratic PTP subsystem behavior. The patch adds a check for the buffer descriptor presence before calling fec_ptp_stop() in both the failure and removal paths, eliminating the fault condition.
Affected Systems
All Linux kernel installations that compile the FEC driver with PTP support are affected, regardless of specific distribution version, until the fix is applied. The issue does not influence other kernel subsystems or drivers.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The flaw is local; an attacker would need to trigger the FEC driver’s failure or removal path, which requires local kernel access. The CVSS score is not publicly available, but the patch removes the fault condition entirely and mitigates the problem.
OpenCVE Enrichment
Debian DLA
Debian DSA