Junglewise Threat Intelligence

CVE-2026-52971: Linux Kernel ENA use-after-free in get_timestamp

CVE-2026-52971 · Severity: info · CVSS 5.5 · Published 2026-06-24

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Amazon Elastic Network Adapter (ENA) driver could allow a local attacker to cause a system crash. The issue occurs when the system attempts to retrieve a network timestamp while the hardware clock feature is being disabled, leading to a memory error. This primarily impacts the availability of the affected server or instance.

Technical details

A use-after-free (UAF) vulnerability exists in the ena_com_phc_get_timestamp function within the Amazon ENA driver (drivers/net/ethernet/amazon/ena/ena_com.c). The root cause is a race condition where the 'active' status and the virtual address pointer for the PHC response are accessed without proper synchronization. If ena_com_phc_destroy() is called concurrently, it can free the DMA memory and nullify the pointer after the initial check but before the spinlock is acquired in the get_timestamp path. This results in a NULL pointer dereference or use-after-free. The fix involves moving the activity check and pointer assignment inside the protected spinlock section.

Affected products

  • Linux Linux 6.17 to 6.18.33, 7.0.10, 7.1

Timeline

  • 2026-05-08: other: Patch authored
  • 2026-06-24: disclosed: CVE published

References