Executive brief
The Linux kernel's precision time protocol (PTP) module for NXP network controllers contains a bug in the periodic output (PEROUT) feature that could cause the system to crash or malfunction. When configuring the period of periodic time pulses, calculation errors allow invalid values to be stored, leading to either division-by-zero exceptions or incorrect hardware register programming that causes unpredictable behavior.
Technical details
The vulnerability involves three interconnected arithmetic flaws in the ptp_netc driver's net_timer_enable_perout() function and related routines. First, max_period validation uses a u64 calculation that exceeds U32_MAX but the actual period value is stored in a u32 struct field, causing silent truncation. Second, a truncated period value of zero reaches netc_timer_set_perout_alarm() where it causes a divide-by-zero in roundup_u64(delta, period). Third, zero period values in netc_timer_enable_periodic_pulse() and netc_timer_enable_fiper() cause unsigned integer wraparound (0xFFFFFFFD) when computing fiper = pp->period - integral_period, mis-programming hardware registers. The fix caps max_period at NETC_TMR_DEFAULT_FIPER (0xFFFFFFFF) to ensure all validated periods fit in u32 without truncation. No known public exploits exist; this is a defensive fix identified through code analysis.
Affected products
- Linux Linux kernel Linux 6.0 through 6.9 and related stable branches
Timeline
- 2026-09-17: disclosed: CVE-2026-90100 published
- 2026-09-14: patched: Fix committed and backported to stable kernels