PT-2026-61154 · Linux · Linux

CVE-2026-63837

·

Published

2026-07-19

·

Updated

2026-07-19

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
net: ena: PHC: Check return code before setting timestamp output
ena phc gettimex64() is setting the output parameter regardless of whether ena com phc get timestamp() succeeded or failed.
When ena com phc get timestamp() returns an error, the timestamp parameter may contain uninitialized stack memory (e.g., when PHC is disabled or in blocked state) or invalid hardware values. Passing these to userspace via the PTP ioctl is both a security issue (information leak) and a correctness bug.
Fix by checking the return code after releasing the lock and only setting the output timestamp on success.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-63837

Affected Products

Linux