SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-80991

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Precision Time Protocol (PTP) clocks, specifically in the ravb driver, where a race condition can lead to a use-after-free scenario during clock teardown. This can result in potential system instability or crashes if the clock is accessed after being freed. Organizations utilizing Linux systems with PTP capabilities, particularly those relying on the ravb driver, should prioritize addressing this vulnerability to ensure system reliability and integrity.

CVE
CVE-2026-80991
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to ptp_clock_event() while ptp_clock_unregister() is freeing it. This can lead to a use-after-free. Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer. Atomically detach it with xchg() before disabling PTP interrupts, then synchronize all IRQs which can invoke ravb_ptp_interrupt() before unregistering the detached clock. A handler which read the old pointer completes before the clock is unregistered, while later handlers read NULL and skip the event.