cbcvebase.
CVE-2026-31396
published 2026-04-03

CVE-2026-31396: In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: net: macb: fix use-after-free access to PTP clock PTP clock is registered on every opening of the interface and destroyed on every closing. However it may be accessed via get_ts_info ethtool call which is possible while the interface is just present in the kernel. BUG: KASAN: use-after-free in ptp_clock_index+0x47/0x50 drivers/ptp/ptp_clock.c:426 Read of size 4 at addr ffff8880194345cc by task syz.0.6/948 CPU: 1 PID: 948 Comm: syz.0.6 Not tainted 6.1.164+ #109 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.1-0-g3208b098f51a-prebuilt.qemu.org 04/01/2014 Call Trace: __dump_stack lib/dump_stack.c:88 [inline] dump_stack_lvl+0x8d/0xba lib/dump_stack.c:106 print_address_description mm/kasan/report.c:316 [inline] print_report+0x17f/0x496 mm/kasan/report.c:420 kasan_report+0xd9/0x180 mm/kasan/report.c:524 ptp_clock_index+0x47/0x50 drivers/ptp/ptp_clock.c:426 gem_get_ts_info+0x138/0x1e0 drivers/net/ethernet/cadence/macb_main.c:3349 macb_get_ts_info+0x68/0xb0 drivers/net/ethernet/cadence/macb_main.c:3371 __ethtool_get_ts_info+0x17c/0x260 net/ethtool/common.c:558 ethtool_get_ts_info net/ethtool/ioctl.c:2367 [inline] __dev_ethtool net/ethtool/ioctl.c:3017 [inline] dev_ethtool+0x2b05/0x6290 net/ethtool/ioctl.c:3095 dev_ioctl+0x637/0x1070 net/core/dev_ioctl.c:510 sock_do_ioctl+0x20d/0x2c0 net/socket.c:1215 sock_ioctl+0x577/0x6d0 net/socket.c:1320 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:870 [inline] __se_sys_ioctl fs/ioctl.c:856 [inline] __x64_sys_ioctl+0x18c/0x210 fs/ioctl.c:856 do_syscall_x64 arch/x86/entry/common.c:46 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:76 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Allocated by task 457: kmalloc include/linux/slab.h:563 [inline] kzalloc include/linux/slab.h:699 [inline] ptp_clock_register+0x144/0x10e0 drivers/ptp/ptp_clock.c:235 gem_ptp_init+0x46f/0x930 drivers/net/ethernet/cadence/macb_ptp.c:375 macb_open+0x901/0x

Affected

58 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.10-1 (forky)linux 6.19.10-1 (forky)
linuxlinux
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 8820ffe0975fd2efbe50453e9179c8e1c33a13d38820ffe0975fd2efbe50453e9179c8e1c33a13d3
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 6b757f345eeea87ed5d8afd6de35b927a1a57a2f6b757f345eeea87ed5d8afd6de35b927a1a57a2f
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 341d01087f821aa0f165fb1ffc8bfe4e50776da7341d01087f821aa0f165fb1ffc8bfe4e50776da7
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 5653af416a48f6c18f9626ae9df96f814f45ff345653af416a48f6c18f9626ae9df96f814f45ff34
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 0bb848d8c64938024e45780f8032f1f67d3a36070bb848d8c64938024e45780f8032f1f67d3a3607
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 1f4714065b2bcbb0a4013fd355b84b848e6cc3451f4714065b2bcbb0a4013fd355b84b848e6cc345
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < eb652535e9ec795ef5c1078f7578eaaed755268beb652535e9ec795ef5c1078f7578eaaed755268b
linuxlinux>= c2594d804d5c8033861d44840673d852d98508c1 < 8da13e6d63c1a97f7302d342c89c4a56a55c70158da13e6d63c1a97f7302d342c89c4a56a55c7015
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.10-16.19.10-1
linuxlinux_kernel>= 4.11 < 5.10.2535.10.253
linuxlinux_kernel>= 5.11 < 5.15.2035.15.203
linuxlinux_kernel>= 5.16 < 6.1.1676.1.167
linuxlinux_kernel>= 6.13 < 6.18.206.18.20
linuxlinux_kernel>= 6.19 < 6.19.106.19.10
linuxlinux_kernel>= 6.2 < 6.6.1306.6.130
linuxlinux_kernel>= 6.7 < 6.12.786.12.78
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.