{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-52971","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.375Z","datePublished":"2026-06-24T16:28:49.637Z","dateUpdated":"2026-08-05T12:32:13.881Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:13.881Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ena: PHC: Fix potential use-after-free in get_timestamp\n\nMove the phc->active check and resp pointer assignment to after\nacquiring the spinlock. Previously, phc->active was checked without\nholding the lock, and resp was cached from ena_dev->phc.virt_addr\nbefore the lock was acquired.\n\nIf ena_com_phc_destroy() runs between the lockless active check and\nthe lock acquisition, it sets active=false, releases the lock, frees\nthe DMA memory, and sets virt_addr=NULL. The get_timestamp path would\nthen read a NULL virt_addr and dereference it.\n\nWith both the active check and the pointer read under the lock,\ndestroy cannot free the memory while get_timestamp is using it."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The vulnerable ENA PHC timestamp path is reached through local PTP clock access such as opening `/dev/ptpN` and invoking `clock_gettime()`/PTP ioctls, not by remote network packets.\nAC:L - The bug is a retryable race between timestamp retrieval and ENA PHC destroy during reset/reinit, and repeated local timestamp calls can exercise the vulnerable window without special memory layout assumptions.\nPR:L - The generic PTP gettime path has no capability check; the attacker only needs local access to the PTP character device/file descriptor, which is a low-privilege local access condition.\nUI:N - No victim action is required once the attacker can access the local PTP clock interface and race it with reset/destruction activity.\nS:U - The vulnerability affects kernel memory within the same host kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - This is a use-after-free of a coherent DMA response buffer whose contents are read back through timestamp retrieval, and under the required higher-severity rule UAF is treated as capable of high confidentiality impact.\nI:H - The stale response pointer is written through after free (`req_id` update) and may corrupt reused kernel/DMA memory, so under the UAF guidance this supports high integrity impact.\nA:H - The stale or NULL/freed pointer dereference can oops or panic the kernel during timestamp retrieval, causing high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/amazon/ena/ena_com.c"],"versions":[{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"95e8ae9af2a61b4e72f5c585bf4c7d8aaf2a2c98","status":"affected","versionType":"git"},{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"ca9ed40f28949353911dcb524ff8fff2f3409c97","status":"affected","versionType":"git"},{"version":"e0ea34158ee8c4f7536cd781010339ff28c0d24c","lessThan":"e42c755582f0960e684298762f0ab927b3778376","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/amazon/ena/ena_com.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/95e8ae9af2a61b4e72f5c585bf4c7d8aaf2a2c98"},{"url":"https://git.kernel.org/stable/c/ca9ed40f28949353911dcb524ff8fff2f3409c97"},{"url":"https://git.kernel.org/stable/c/e42c755582f0960e684298762f0ab927b3778376"}],"title":"net: ena: PHC: Fix potential use-after-free in get_timestamp","x_generator":{"engine":"bippy-1.2.0"}}}}