Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's ENA (Elastic Network Adapter) driver can lead to an information leak. The issue arises in the PHC (Precision Time Protocol Hardware Clock) support implementation. The function 'ena_phc_gettimex64()' improperly sets the output timestamp parameter without verifying if the preceding timestamp retrieval function succeeded. This oversight can result in the output containing uninitialized memory or invalid hardware values. When these erroneous timestamps are conveyed to userspace through the PTP ioctl, it creates a security risk by leaking sensitive information and introduces a correctness bug. The vulnerability affects the Linux kernel stable tree.
The vulnerability can be exploited to leak uninitialized stack memory or invalid hardware values to userspace, creating a potential security risk and correctness issue.
Users can upgrade to the latest version of the Linux kernel where this vulnerability has been addressed. The specific commit that resolves this issue is '24a08d7d6218d60c033015cf4870b6096446e734', which is included in the official Linux kernel repositories.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.