CVE-2026-90056

Unknown

Last modified

CVE-2026-90056 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ptp_init() is only called when fep->bufdesc_ex is available. However, fec_probe() unconditionally calls fec_ptp_stop() on the failed_init path, and fec_drv_remove() unconditionally calls fec_ptp_stop() during device removal. Check fep->bufdesc_ex before calling fec_ptp_stop() in both paths to avoid stopping PTP when it was not initialized..

Description

In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ptp_init() is only called when fep->bufdesc_ex is available. However, fec_probe() unconditionally calls fec_ptp_stop() on the failed_init path, and fec_drv_remove() unconditionally calls fec_ptp_stop() during device removal. Check fep->bufdesc_ex before calling fec_ptp_stop() in both paths to avoid stopping PTP when it was not initialized.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 0dc8b3a395c3a749ab62c078f2fd54a402ae7e2b; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 1973f108c481fab9bdc7daa6c77442af4a7388ab; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 0602a4c238d2b6ed6e2bf5fa8ef7fa0203883dac; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 7566789664813c1778f0d4b7e0539fd863ea450c; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 383f699a86fd04458dc47d10578c17e94f63d92f; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 1f9639caeece703012bdb23975ebedf70f426269; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < 5975009651c4e5ec1492612962d0dd3dc86f6bda; >= 32cba57ba74be58589aeb4cb6496183e46a5e3e5, < dd890ae29299636fb037276fc1b5238698d08b03; 9561b28349a22c808c3ce25eaed4d132104bafb7; >= 3.18.99, < 3.19
LinuxLinux4.2

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-90056?
In the Linux kernel, the following vulnerability has been resolved: net: fec: only stop PTP if it was initialized fec_ptp_init() is only called when fep->bufdesc_ex is available. However, fec_probe() unconditionally calls fec_ptp_stop() on the failed_init path, and fec_drv_remove() unconditionally calls fec_ptp_stop() during device removal. Check fep->bufdesc_ex before calling fec_ptp_stop() in both paths to avoid stopping PTP when it was not initialized.
How severe is CVE-2026-90056?
Severity scoring for CVE-2026-90056 is pending analysis.
How do I fix CVE-2026-90056?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-90056?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST