GHSA-fv8x-x8x6-cwcrunknown
In the Linux kernel, the following vulnerability has been resolved: ice: fix PTP Call Trace...
🔗 CVE IDs covered (1)
📋 Description
In the Linux kernel, the following vulnerability has been resolved:
ice: fix PTP Call Trace during PTP release
If a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then ice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will result in the following PTP release call trace during driver unload:
kernel BUG at lib/list_debug.c:52!
ice_ptp_release+0x332/0x3c0 [ice]
ice_deinit_features.part.0+0x10e/0x120 [ice]
ice_remove+0x100/0x220 [ice]
This was observed when passing PF1 through to a VM. ice_ptp_init() fails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.
Fix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and returning without error, preventing the invalid state transition to ICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from ICE_PTP_RESETTING after a failed rebuild.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-68133
- https://git.kernel.org/stable/c/14fceda28069fdbe1bb49cdb6e1774892b583348
- https://git.kernel.org/stable/c/7d517b255f669cedd09830214d55f2f413b34481
- https://git.kernel.org/stable/c/e4406cbdd915f702d2ed9ee8b30683a16b06c6ac
- https://git.kernel.org/stable/c/f6a7e00b81e35ef1325234925f2fe1e53b466f92
- https://github.com/advisories/GHSA-fv8x-x8x6-cwcr