{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80992","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.811Z","datePublished":"2026-09-11T19:42:48.855Z","dateUpdated":"2026-09-14T11:59:33.146Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:33.146Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: avoid dereferencing an invalid PTP clock\n\nThe PTP clock is unavailable before the first open, so querying its\nindex can dereference a NULL pointer. Registration failures can also\nleave an error pointer in priv->ptp.clock.\n\nCache the PHC index separately and report -1 while no clock is\nregistered. Normalize registration errors to NULL and preserve the\nstatic timestamping capabilities."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - ravb_get_ts_info() is reached only via local SIOCETHTOOL ETHTOOL_GET_TS_INFO, ethtool netlink TSINFO_GET, SO_TIMESTAMPING BIND_PHC, or taprio setup on the ravb netdev. Received Ethernet/PTP packets never enter this path.\nAC:L - ethtool timestamp-info on a never-opened ravb interface deterministically calls ptp_clock_index(NULL), and after a normal open/close ravb_ptp_stop() leaves a dangling priv->ptp.clock that the same query dereferences. The attacker does not need a race or a rare config.\nPR:L - ETHTOOL_GET_TS_INFO is on the ethtool ioctl allow-list that skips CAP_NET_ADMIN, and ETHTOOL_MSG_TSINFO_GET has no GENL admin flag, so an unprivileged local user can trigger it. Interface cycling is privileged, but the down/never-opened state exists after normal system management.\nUI:N - The attacker issues the ethtool ioctl/netlink query (or SO_TIMESTAMPING BIND_PHC) directly against the existing ravb netdev. No separate victim action is required.\nS:U - The defect is in the ravb kernel Ethernet/PTP driver and impacts the same kernel. It is not a guest-to-host, IOMMU, or other cross-authority boundary bypass.\nC:H - After ndo_stop, ravb_ptp_stop() unregisters and kfree's struct ptp_clock via ptp_clock_release() but leaves priv->ptp.clock set, so a later ptp_clock_index() is a kernel heap UAF read. Kernel scoring treats UAFs as high confidentiality because freed-object reuse can yield disclosure primitives.\nI:H - The get_ts_info hit is a stale read of ptp_clock.index, but after close the object is a freed heap ptp_clock. Kernel scoring treats that UAF as high integrity impact because heap reuse can be leveraged toward write or control-flow primitives.\nA:H - Before first open, ptp_clock_index(NULL) oopses; a failed ptp_clock_register() leaves an ERR_PTR that is also dereferenced; and the post-close dangling pointer is a UAF that can panic. Any of these kernel crashes is high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/renesas/ravb.h","drivers/net/ethernet/renesas/ravb_main.c","drivers/net/ethernet/renesas/ravb_ptp.c"],"versions":[{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"29ffd972531f8e6e0edf4ea3496190acff9fc9c2","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"bf3308416a2be85dcc9965b614a745b40beeff14","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"fc710f89a644e030a7ca15343176ca862fd61b9d","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"8d4d06d6e2b501cb8e30ed3b1924c470358e8052","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"0aaa53936419cf0c19c670387fc6d431e042a1b6","status":"affected","versionType":"git"},{"version":"a0d2f20650e81407d8e51ad2cbdc492861c74e9c","lessThan":"1f77af0aaf277413ff32f6ff8c2c4282bd64c897","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/net/ethernet/renesas/ravb.h","drivers/net/ethernet/renesas/ravb_main.c","drivers/net/ethernet/renesas/ravb_ptp.c"],"versions":[{"version":"4.2","status":"affected"},{"version":"0","lessThan":"4.2","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.2","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/29ffd972531f8e6e0edf4ea3496190acff9fc9c2"},{"url":"https://git.kernel.org/stable/c/bf3308416a2be85dcc9965b614a745b40beeff14"},{"url":"https://git.kernel.org/stable/c/fc710f89a644e030a7ca15343176ca862fd61b9d"},{"url":"https://git.kernel.org/stable/c/8d4d06d6e2b501cb8e30ed3b1924c470358e8052"},{"url":"https://git.kernel.org/stable/c/0aaa53936419cf0c19c670387fc6d431e042a1b6"},{"url":"https://git.kernel.org/stable/c/1f77af0aaf277413ff32f6ff8c2c4282bd64c897"}],"title":"net: ravb: avoid dereferencing an invalid PTP clock","x_generator":{"engine":"bippy-1.2.0"}}}}