← All Advisories

CVE-2026-97963

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97963

Key Details

CVECVE-2026-97963
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net: stmmac: initialize ptp_lock at probe time

priv->ptp_lock is only initialized in stmmac_ptp_register(), which runs

during __stmmac_open(). However, the lock is also used while the

interface is down and has never been opened: tc_taprio_configure()

invokes the PTP gettime64() callback to compute the EST base time when

offloading a TAPRIO schedule, and stmmac_get_time() takes

priv->ptp_lock. Using an uninitialized rwlock is undefined behaviour.

Move the rwlock_init() to __stmmac_dvr_probe(), together with the other

private locks, so that ptp_lock is always valid regardless of the

interface state. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97963
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97963