net: ravb: avoid dereferencing an invalid PTP clock
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.2%
exploitation probability
0.2%top 94% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
net: ravb: avoid dereferencing an invalid PTP clock
The PTP clock is unavailable before the first open, so querying its
index can dereference a NULL pointer. Registration failures can also
leave an error pointer in priv->ptp.clock.
Cache the PHC index separately and report -1 while no clock is
registered. Normalize registration errors to NULL and preserve the
static timestamping capabilities.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/0aaa53936419cf0c19c670387fc6d431e042a1b6https://git.kernel.org/stable/c/1f77af0aaf277413ff32f6ff8c2c4282bd64c897https://git.kernel.org/stable/c/29ffd972531f8e6e0edf4ea3496190acff9fc9c2https://git.kernel.org/stable/c/8d4d06d6e2b501cb8e30ed3b1924c470358e8052https://git.kernel.org/stable/c/bf3308416a2be85dcc9965b614a745b40beeff14https://git.kernel.org/stable/c/fc710f89a644e030a7ca15343176ca862fd61b9d