Description
In the Linux kernel, the following vulnerability has been resolved:

ptp: netc: fix period truncation and potential divide-by-zero in PEROUT

The max_period bound in net_timer_enable_perout() was computed as:

max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period;

which exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for
the default 333333333 Hz clock). A period_ns that passes this check but
exceeds U32_MAX is then silently truncated when stored into the u32
struct netc_pp::period field.

A truncated value of zero can reach netc_timer_set_perout_alarm(), where
the local u32 period variable would also be 0, causing a divide-by-zero
in roundup_u64(delta, period) whenever the stime < min_time branch is
taken (which always happens for a start time of {0, 0}).

Additionally, netc_timer_enable_periodic_pulse() and
netc_timer_enable_fiper() both compute:

fiper = pp->period - integral_period;

A zero pp->period results in an unsigned wraparound to 0xFFFFFFFD,
mis-programming the FIPER hardware register.

Fix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER
(0xFFFFFFFF). This ensures that any period_ns passing the range check
fits in a u32 without truncation, so the stored value is always valid
and non-zero. The accepted range is reduced by integral_period ns
(typically only a few nanoseconds), which is negligible in practice.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A calculation error inside the Linux kernel’s PTP netc timer driver can cause an integer overflow when computing the maximum permissible period for periodic output. The overflow silently truncates the computed value to zero, which is subsequently used in a division operation, resulting in an undefined divide‑by‑zero during timer initialization. Additionally, a zero period can wrap around in unsigned arithmetic, misprogramming the hardware register. The outcome is a kernel panic or unstable state that renders the host unreachable.

Affected Systems

The vulnerability affects any Linux kernel that includes the netc PTP timer subsystem before the commit that caps the maximum period. All recent kernel versions that expose the netc timer driver are at risk. Because the CPE string references the generic linux_kernel, any unpatched kernel release presenting this driver is a valid target.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of active exploitation. Because the flaw occurs in internal calculations of the netc timer driver, an attacker would need to manipulate kernel data structures or trigger a period reset that leads to the divide‑by‑zero condition. No public exploitation methods are documented in the referenced resources. If successfully triggered, the kernel would likely panic or experience unstable behavior, effectively denying service to the host.

Generated by OpenCVE AI on September 20, 2026 at 03:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the netc PTP fix
  • If a kernel upgrade cannot be applied immediately, unload or blacklist the netc module to prevent the faulty driver from loading
  • If the module cannot be unloaded, disable PTP timer control via sysfs or configuration so the driver cannot manipulate timer periods
  • Continuously monitor system logs for kernel panic or divide‑by‑zero messages that may indicate residual issues

Generated by OpenCVE AI on September 20, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
CWE-368

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ptp: netc: fix period truncation and potential divide-by-zero in PEROUT The max_period bound in net_timer_enable_perout() was computed as: max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period; which exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for the default 333333333 Hz clock). A period_ns that passes this check but exceeds U32_MAX is then silently truncated when stored into the u32 struct netc_pp::period field. A truncated value of zero can reach netc_timer_set_perout_alarm(), where the local u32 period variable would also be 0, causing a divide-by-zero in roundup_u64(delta, period) whenever the stime < min_time branch is taken (which always happens for a start time of {0, 0}). Additionally, netc_timer_enable_periodic_pulse() and netc_timer_enable_fiper() both compute: fiper = pp->period - integral_period; A zero pp->period results in an unsigned wraparound to 0xFFFFFFFD, mis-programming the FIPER hardware register. Fix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER (0xFFFFFFFF). This ensures that any period_ns passing the range check fits in a u32 without truncation, so the stored value is always valid and non-zero. The accepted range is reduced by integral_period ns (typically only a few nanoseconds), which is negligible in practice.
Title ptp: netc: fix period truncation and potential divide-by-zero in PEROUT
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:06:11.515Z

Reserved: 2026-09-11T19:38:34.786Z

Link: CVE-2026-90100

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:01.680

Modified: 2026-09-17T17:17:01.680

Link: CVE-2026-90100

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:00:09Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-368

    Context Switching Race Condition