« Volver al listado

CVE-2026-90100

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ptp: netc: fix period truncation and potential divide-by-zero in PEROUT

The max_period bound in net_timer_enable_perout() was computed as:

which exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for the default 333333333 Hz clock). A period_ns that passes this check but exceeds U32_MAX is then silently truncated when stored into the u32 struct netc_pp::period field.

A truncated value of zero can reach netc_timer_set_perout_alarm(), where the local u32 period variable would also be 0, causing a divide-by-zero in roundup_u64(delta, period) whenever the stime < min_time branch is taken (which always happens for a start time of {0, 0}).

Leer descripción completaMostrar menos

Additionally, netc_timer_enable_periodic_pulse() and netc_timer_enable_fiper() both compute:

A zero pp->period results in an unsigned wraparound to 0xFFFFFFFD, mis-programming the FIPER hardware register.

Fix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER (0xFFFFFFFF). This ensures that any period_ns passing the range check fits in a u32 without truncation, so the stored value is always valid and non-zero. The accepted range is reduced by integral_period ns (typically only a few nanoseconds), which is negligible in practice.

Detalles técnicos trazas, registros y código del informe original
  max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period;

  fiper = pp->period - integral_period;

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90100",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "671e266835b8a87d6cc2c6db962de23783405dd8",
              "lessThan": "51fe3fe0ffec033bd831c71d9bee3dee827e491c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "671e266835b8a87d6cc2c6db962de23783405dd8",
              "lessThan": "08988d1941e180f0ad30d91233cb64f3418ba23c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "671e266835b8a87d6cc2c6db962de23783405dd8",
              "lessThan": "777dbc9914b2f003f1d44af80c7a4a395c5961b2",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/ptp/ptp_netc.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/ptp/ptp_netc.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:17:01.680",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/08988d1941e180f0ad30d91233cb64f3418ba23c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/51fe3fe0ffec033bd831c71d9bee3dee827e491c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/777dbc9914b2f003f1d44af80c7a4a395c5961b2",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nptp: netc: fix period truncation and potential divide-by-zero in PEROUT\n\nThe max_period bound in net_timer_enable_perout() was computed as:\n\n  max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period;\n\nwhich exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for\nthe default 333333333 Hz clock). A period_ns that passes this check but\nexceeds U32_MAX is then silently truncated when stored into the u32\nstruct netc_pp::period field.\n\nA truncated value of zero can reach netc_timer_set_perout_alarm(), where\nthe local u32 period variable would also be 0, causing a divide-by-zero\nin roundup_u64(delta, period) whenever the stime < min_time branch is\ntaken (which always happens for a start time of {0, 0}).\n\nAdditionally, netc_timer_enable_periodic_pulse() and\nnetc_timer_enable_fiper() both compute:\n\n  fiper = pp->period - integral_period;\n\nA zero pp->period results in an unsigned wraparound to 0xFFFFFFFD,\nmis-programming the FIPER hardware register.\n\nFix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER\n(0xFFFFFFFF). This ensures that any period_ns passing the range check\nfits in a u32 without truncation, so the stored value is always valid\nand non-zero. The accepted range is reduced by integral_period ns\n(typically only a few nanoseconds), which is negligible in practice."
    }
  ],
  "lastModified": "2026-09-17T17:17:01.680",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}