Impact
A calculation error inside the Linux kernel’s PTP netc timer driver can cause an integer overflow when computing the maximum permissible period for periodic output. The overflow silently truncates the computed value to zero, which is subsequently used in a division operation, resulting in an undefined divide‑by‑zero during timer initialization. Additionally, a zero period can wrap around in unsigned arithmetic, misprogramming the hardware register. The outcome is a kernel panic or unstable state that renders the host unreachable.
Affected Systems
The vulnerability affects any Linux kernel that includes the netc PTP timer subsystem before the commit that caps the maximum period. All recent kernel versions that expose the netc timer driver are at risk. Because the CPE string references the generic linux_kernel, any unpatched kernel release presenting this driver is a valid target.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of active exploitation. Because the flaw occurs in internal calculations of the netc timer driver, an attacker would need to manipulate kernel data structures or trigger a period reset that leads to the divide‑by‑zero condition. No public exploitation methods are documented in the referenced resources. If successfully triggered, the kernel would likely panic or experience unstable behavior, effectively denying service to the host.
OpenCVE Enrichment