Executive brief
A vulnerability exists in the Linux kernel's Marvell OcteonTX2 network driver. This flaw occurs during the shutdown or removal of the network interface, where internal cleanup processes may conflict with active background tasks. An attacker could potentially exploit this race condition to cause a system crash or execute unauthorized actions, impacting system stability and security.
Technical details
A use-after-free (UAF) vulnerability exists in the octeontx2-pf driver within the Linux kernel. The root cause is the use of cancel_delayed_work() in the otx2_ptp_destroy() function, which fails to wait for the 'synctstamp_work' task to finish if it is already executing. This creates a race condition where the 'otx2_ptp' structure is freed while the background task attempts to dereference it in otx2_sync_tstamp(). An attacker with local access could trigger this during device removal or driver unloading to cause a kernel panic or potentially achieve local privilege escalation. The issue is resolved by replacing the call with cancel_delayed_work_sync() to ensure proper synchronization.
Affected products
- Linux Linux Kernel 2958d17a8984 to f8b468715102
Timeline
- 2025-09-17: patched: Initial patch authored
- 2025-10-04: disclosed: CVE published
References
- https://git.kernel.org/stable/c/2786879aebf363806a13d41e8d5f99202ddd23d9
- https://git.kernel.org/stable/c/5ca20bb7b4bde72110c3ae78423cbfdd0157aa36
- https://git.kernel.org/stable/c/d2cfefa14ce8137b17f99683f968bebf134b6a48
- https://git.kernel.org/stable/c/f8b4687151021db61841af983f1cb7be6915d4ef
- https://git.kernel.org/stable/c/ff27e23b311fed4d25e3852e27ba693416d4c7b3