Description
In the Linux kernel, the following vulnerability has been resolved:

net: fec: only stop PTP if it was initialized

fec_ptp_init() is only called when fep->bufdesc_ex is available.
However, fec_probe() unconditionally calls fec_ptp_stop() on the
failed_init path, and fec_drv_remove() unconditionally calls
fec_ptp_stop() during device removal.

Check fep->bufdesc_ex before calling fec_ptp_stop() in both paths
to avoid stopping PTP when it was not initialized.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel fault due to uninitialized PTP stop
Action: Upgrade Kernel
AI Analysis

Impact

The Linux kernel FEC driver contains a flaw where fec_ptp_stop() is called without confirming that the PTP clock was initialized. This absence of a guard causes the driver to attempt stopping a PTP clock that was never started, potentially leading to a kernel fault or erratic PTP subsystem behavior. The patch adds a check for the buffer descriptor presence before calling fec_ptp_stop() in both the failure and removal paths, eliminating the fault condition.

Affected Systems

All Linux kernel installations that compile the FEC driver with PTP support are affected, regardless of specific distribution version, until the fix is applied. The issue does not influence other kernel subsystems or drivers.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low likelihood of exploitation. The flaw is local; an attacker would need to trigger the FEC driver’s failure or removal path, which requires local kernel access. The CVSS score is not publicly available, but the patch removes the fault condition entirely and mitigates the problem.

Generated by OpenCVE AI on September 20, 2026 at 05:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that contains the patch or apply the individual changes from the kernel commit history that guard against stopping PTP when it has not been initialized.
  • If an update is not available, apply the kernel patch directly to the FEC driver source and rebuild the kernel to include the guard.
  • Refresh the system’s kernel package repository and apply any pending security updates for the Linux kernel.

Generated by OpenCVE AI on September 20, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ptp_init() is only called when fep->bufdesc_ex is available. However, fec_probe() unconditionally calls fec_ptp_stop() on the failed_init path, and fec_drv_remove() unconditionally calls fec_ptp_stop() during device removal. Check fep->bufdesc_ex before calling fec_ptp_stop() in both paths to avoid stopping PTP when it was not initialized.
Title net: fec: only stop PTP if it was initialized
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:41.003Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:54.177

Modified: 2026-09-17T17:16:54.177

Link: CVE-2026-90056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T06:00:14Z

Weaknesses