net: stmmac: initialize ptp_lock at probe time

Summary

CVECVE-2026-97963
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-25 11:17:24 UTC
Updated2026-10-03 11:18:21 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: stmmac: initialize ptp_lock at probe time priv->ptp_lock is only initialized in stmmac_ptp_register(), which runs during __stmmac_open(). However, the lock is also used while the interface is down and has never been opened: tc_taprio_configure() invokes the PTP gettime64() callback to compute the EST base time when offloading a TAPRIO schedule, and stmmac_get_time() takes priv->ptp_lock. Using an uninitialized rwlock is undefined behaviour. Move the rwlock_init() to __stmmac_dvr_probe(), together with the other private locks, so that ptp_lock is always valid regardless of the interface state.

Risk And Classification

EPSS: 0.001680000 probability, percentile 0.054770000 (date 2026-10-03)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a ee33e424d4932c70f103b94a46b685923f236f65 git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a 7ced87834f3a58761d4bbcabf8326478548e6a54 git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a 79fb5bcc50996964e076dffbdc24b7d2c06bd957 git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a 420315413b29635de1d4ea4142e410e6465260f3 git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a 25cc0096efba83b4e0e6fa50f03e9543b41e9d3d git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a b1986595cf827c38ff929e22fbc9ca8f76379306 git Not specified
CNA Linux Linux affected b60189e0392fa06348911077ef281eb2b1047b6a 0338c68e22abd2ee509ec2e32508a50896618c32 git Not specified
CNA Linux Linux affected 5.6 Not specified
CNA Linux Linux unaffected 5.6 semver Not specified
CNA Linux Linux unaffected 5.15.222 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.189 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.158 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.111 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.53 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.7 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/0338c68e22abd2ee509ec2e32508a50896618c32 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b1986595cf827c38ff929e22fbc9ca8f76379306 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/7ced87834f3a58761d4bbcabf8326478548e6a54 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/25cc0096efba83b4e0e6fa50f03e9543b41e9d3d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/420315413b29635de1d4ea4142e410e6465260f3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ee33e424d4932c70f103b94a46b685923f236f65 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/79fb5bcc50996964e076dffbdc24b7d2c06bd957 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report