Executive brief
A vulnerability in the Linux kernel's Amazon Elastic Network Adapter (ENA) driver could allow local users to access sensitive information from the system's memory. The issue occurs when the system fails to properly clear or validate internal data before sending it to a user-level application. This could result in the exposure of small amounts of kernel memory, potentially aiding in more complex attacks or leaking system state information.
Technical details
A vulnerability in the ena_phc_gettimex64() function within the Amazon ENA driver (drivers/net/ethernet/amazon/ena/ena_phc.c) fails to validate the return code of ena_com_phc_get_timestamp(). If the latter function fails (e.g., when PHC is disabled or blocked), the driver proceeds to copy uninitialized stack memory or invalid hardware values into the output parameter provided to userspace via the PTP ioctl. This constitutes a classic information leak of kernel stack data. The fix involves verifying the return code after releasing the spinlock and only populating the output timestamp on success. Patches have been backported to various stable kernel branches.
Affected products
- Linux Linux Kernel 6.17 to 6.18.33, 7.0.10
Timeline
- 2026-05-07: other: Initial patch authored
- 2026-07-19: disclosed: CVE published