Executive brief
A vulnerability was identified in the Linux kernel's Pulse Per Second (PPS) subsystem, which is used for high-precision time synchronization. Under specific error conditions during device registration, the system may trigger a kernel warning or experience a 'double free' memory error. This could lead to a system crash or instability, potentially impacting the availability of services relying on precise timing.
Technical details
A vulnerability exists in the Linux kernel PPS (Pulse Per Second) subsystem due to improper ordering of device registration and release hook assignment. In `pps_register_cdev`, the `release` hook was being set after `device_register()`. If `device_register()` fails, the subsequent `put_device()` call triggers a kernel warning because the release function is missing. Additionally, a double-free vulnerability existed in `pps_register_source()` where `kfree_pps` was incorrectly called during failure cases. An attacker with local access could potentially trigger these error paths to cause a Denial of Service (DoS) via kernel panic. The fix ensures the release hook is set before registration and removes the redundant kfree call.
Affected products
- Linux Linux Kernel 6.17.0-rc3+; V3.1.6 (Siemens SIMATIC)
Timeline
- 2025-08-30: patched: Initial patch authored by Wang Liang
- 2025-10-28: advisory: CVE published
References
- https://git.kernel.org/stable/c/0f97564a1fb62f34b3b498e2f12caffbe99c004a
- https://git.kernel.org/stable/c/125527db41805693208ee1aacd7f3ffe6a3a489c
- https://git.kernel.org/stable/c/2a194707ca27a3b0523023fa8b446e5ec922dc51
- https://git.kernel.org/stable/c/38c7bb10aae5118dd48fa7a82f7bf93839bcc320
- https://git.kernel.org/stable/c/4cbd7450a22c5ee4842fc4175ad06c0c82ea53a8
- https://git.kernel.org/stable/c/b0531cdba5029f897da5156815e3bdafe1e9b88d
- https://git.kernel.org/stable/c/cf71834a0cfc394c72d62fd6dbb470ee13cf8f5e