Junglewise Threat Intelligence

CVE-2026-68134: Linux kernel s390 ptp driver missing facility check

CVE-2026-68134 · Severity: high · CVSS 7.3 · Published 2026-08-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's s390 PTP (Precision Time Protocol) driver failed to validate hardware facility availability before registering a physical clock. This could allow the driver to attempt operations on systems lacking required hardware support, potentially causing system crashes or unpredictable behavior on affected s390 systems.

Technical details

The vulnerability is a missing input validation / facility check in the ptp_s390 driver (drivers/ptp/ptp_s390.c). The ptp_s390_init() function registered the physical clock (ptp_qpt_clock) without checking whether facility 28 was installed on the system or whether the PTFF QPT query returned success. The fix adds checks for test_facility(28) and ptff_query(PTFF_QPT) before attempting registration, and adds a null-check guard in ptp_s390_exit() to prevent unregistering a null pointer. This is a local/kernel-level issue affecting s390 systems without the required hardware facility, no network attack vector.

Affected products

  • Linux Linux kernel multiple kernel versions (s390 architecture)

Timeline

  • 2026-08-10: disclosed
  • 2026-08-03: patched: Fix committed upstream

References

Related threats