{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80991","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.811Z","datePublished":"2026-09-11T19:42:48.187Z","dateUpdated":"2026-09-13T06:28:55.151Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-13T06:28:55.151Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: serialize PTP clock teardown\n\nravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to\nptp_clock_event() while ptp_clock_unregister() is freeing it. This can\nlead to a use-after-free.\n\nUse READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer.\nAtomically detach it with xchg() before disabling PTP interrupts, then\nsynchronize all IRQs which can invoke ravb_ptp_interrupt() before\nunregistering the detached clock.\n\nA handler which read the old pointer completes before the clock is\nunregistered, while later handlers read NULL and skip the event."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The UAF is reached from the ravb gPTP IRQ handler (ravb_interrupt/ravb_multi_interrupt → ravb_ptp_interrupt → ptp_clock_event) racing local ravb_ptp_stop teardown (close, suspend, TX-timeout work, ethtool ringparam). GIS_PTCF capture IRQs come from the on-chip AVB timer, not from parsing received Ethernet frames.\nAC:L - The attacker drives both sides: ordinary sockets or automotive idle autosuspend trigger ravb_ptp_stop, and PTP_EXTTS_REQUEST on /dev/ptpX (write fd, no CAP_SYS_TIME) enables capture IRQs. Pre-fix stop cleared GIC then called ptp_clock_unregister without synchronize_irq, so an in-flight handler can be raced repeatedly.\nPR:L - On Renesas R-Car/RZ automotive and industrial systems, unprivileged traffic arms ravb_tx_timeout_work and platform autosleep calls ravb_close without CAP_NET_ADMIN; EXTTS enable needs only a writable PTP chardev, not host root. This matches CVE-2025-21801 and CVE-2023-52509 ravb scoring.\nUI:N - Interface teardown runs from the TX watchdog or from automatic suspend/idle power management on the affected platforms, with no separate victim user action required.\nS:U - The use-after-free corrupts the host kernel's struct ptp_clock heap object within a single kernel security authority and does not cross a VM, IOMMU, or sandbox boundary.\nC:H - ptp_clock_event takes ptp->tsevqs_lock and walks the timestamp queue list after ptp_clock_release has kfree'd the clock, so reclaiming that slab provides an arbitrary kernel-memory read primitive.\nI:H - The same IRQ-context UAF writes via enqueue_external_timestamp into list-queue objects the attacker can reclaim, yielding a kernel heap write primitive suitable for control-flow hijacking.\nA:H - Use-after-free of struct ptp_clock in hardirq context causes a kernel oops or panic and takes down the system's primary Ethernet interface."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/renesas/ravb.h","drivers/net/ethernet/renesas/ravb_main.c","drivers/net/ethernet/renesas/ravb_ptp.c"],"versions":[{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"695acb5534a9e366efb47b40c7487fc56488b09b","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"67a82e6f886beed0de8f8da08bb767e68fba952d","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"66b50c31419e7946e9aa325a468ad9b64c961a25","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"1cb9663789c5b7a12fcd419fcca6d6254c398252","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/renesas/ravb.h","drivers/net/ethernet/renesas/ravb_main.c","drivers/net/ethernet/renesas/ravb_ptp.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/695acb5534a9e366efb47b40c7487fc56488b09b"},{"url":"https://git.kernel.org/stable/c/67a82e6f886beed0de8f8da08bb767e68fba952d"},{"url":"https://git.kernel.org/stable/c/66b50c31419e7946e9aa325a468ad9b64c961a25"},{"url":"https://git.kernel.org/stable/c/1cb9663789c5b7a12fcd419fcca6d6254c398252"}],"title":"net: ravb: serialize PTP clock teardown","x_generator":{"engine":"bippy-1.2.0"}}}}