Answer in brief
CVE-2026-80991 records a Unknown severity vulnerability in net: ravb: serialize PTP clock teardown. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a0d2f20650e81407d8e51ad2cbdc492861c74e9c <695acb5534a9e366efb47b40c7487fc56488b09b || >=a0d2f20650e81407d8e51ad2cbdc492861c74e9c <67a82e6f886beed0de8f8da08bb767e68fba952d || >=a0d2f20650e81407d8e51ad2cbdc492861c74e9c <66b50c31419e7946e9aa325a468ad9b64c961a25 || >=a0d2f20650e81407d8e51ad2cbdc492861c74e9c <1cb9663789c5b7a12fcd419fcca6d6254c398252 | 695acb5534a9e366efb47b40c7487fc56488b09b, 67a82e6f886beed0de8f8da08bb767e68fba952d, 66b50c31419e7946e9aa325a468ad9b64c961a25, 1cb9663789c5b7a12fcd419fcca6d6254c398252 |
| Linux/Linuxgeneric | 4.2 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: net: ravb: serialize PTP clock teardown ravb_ptp_interrupt() can race with ravb_ptp_stop() and pass the clock to ptp_clock_event() while ptp_clock_unregister() is freeing it. This can lead to a use-after-free. Use READ_ONCE() and WRITE_ONCE() for lockless access to the clock pointer. Atomically detach it with xchg() before disabling PTP interrupts, then synchronize all IRQs which can invoke ravb_ptp_interrupt() before unregistering the detached clock. A handler which read the old pointer completes before the clock is unregistered, while later handlers read NULL and skip the event.
Quoted source text, attributed separately from HOL analysis.