CVE-2026-23210

Aliases:UBUNTU-CVE-2026-23210DEBIAN-CVE-2026-23210CGA-2fx2-j6c8-fm8qCGA-7vmj-3m4p-7597CGA-8mgv-4vr9-2x85CGA-96x4-c7xj-m88mCGA-c5hh-4ccg-239qCGA-c8fp-w9rr-cpwgCGA-crfp-ghp2-fmhjCGA-f584-56x3-2p3fCGA-gc9w-c5hq-v2vwCGA-gv6p-f63q-c33vCGA-h5r6-x2jw-m77hCGA-h98q-pv3q-7mwxCGA-hg2c-8995-hrqrCGA-j39f-2hwq-p5jhCGA-mr77-3xqg-ppg3CGA-q2qg-7h7v-jv72CGA-q86c-98pf-272fCGA-rvh5-5cf5-9xr3CGA-v76x-mvh9-25q3CGA-w83g-r2xf-66p7CGA-w8xg-g5m5-r9mpCGA-wq2x-35r6-2p95CGA-wx89-xw64-m4wxCGA-x626-cxr6-v97qCGA-xr34-27g5-qmpr
Modified
Published: 14 Feb 2026, 16:27
Last modified:11 Jun 2026, 18:44

Vulnerability Summary

Overall Risk (default)
low
19/100
CVSS Score
4.7 MEDIUM
v3.1 (nvd)
EPSS Score
0.11% LOW
0% probability +0.09%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Feb 2026, 16:27
Published
Vulnerability first disclosed
11 Jun 2026, 18:44
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ice: Fix PTP NULL pointer dereference during VSI rebuild Fix race condition where PTP periodic work runs while VSI is being rebuilt, accessing NULL vsi->rx_rings. The sequence was: 1. ice_ptp_prepare_for_reset() cancels PTP work 2. ice_ptp_rebuild() immediately queues PTP work 3. VSI rebuild happens AFTER ice_ptp_rebuild() 4. PTP work runs and accesses NULL vsi->rx_rings Fix: Keep PTP work cancelled during rebuild, only queue it after VSI rebuild completes in ice_rebuild(). Added ice_ptp_queue_work() helper function to encapsulate the logic for queuing PTP work, ensuring it's only queued when PTP is supported and the state is ICE_PTP_READY. Error log: [ 121.392544] ice 0000:60:00.1: PTP reset successful [ 121.392692] BUG: kernel NULL pointer dereference, address: 0000000000000000 [ 121.392712] #PF: supervisor read access in kernel mode [ 121.392720] #PF: error_code(0x0000) - not-present page [ 121.392727] PGD 0 [ 121.392734] Oops: Oops: 0000 [#1] SMP NOPTI [ 121.392746] CPU: 8 UID: 0 PID: 1005 Comm: ice-ptp-0000:60 Tainted: G S 6.19.0-rc6+ #4 PREEMPT(voluntary) [ 121.392761] Tainted: [S]=CPU_OUT_OF_SPEC [ 121.392773] RIP: 0010:ice_ptp_update_cached_phctime+0xbf/0x150 [ice] [ 121.393042] Call Trace: [ 121.393047] <TASK> [ 121.393055] ice_ptp_periodic_work+0x69/0x180 [ice] [ 121.393202] kthread_worker_fn+0xa2/0x260 [ 121.393216] ? __pfx_ice_ptp_periodic_work+0x10/0x10 [ice] [ 121.393359] ? __pfx_kthread_worker_fn+0x10/0x10 [ 121.393371] kthread+0x10d/0x230 [ 121.393382] ? __pfx_kthread+0x10/0x10 [ 121.393393] ret_from_fork+0x273/0x2b0 [ 121.393407] ? __pfx_kthread+0x10/0x10 [ 121.393417] ret_from_fork_asm+0x1a/0x30 [ 121.393432] </TASK>

CVSS Metrics

  • v3.1MEDIUMScore: 4.7CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.11% Percentile: 1%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.77-r2 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.80-r0

  • chainguardlinux-azure-6.12

    < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.80-r0 | < 6.12.77-r2

  • chainguardlinux-gcp-6.12

    < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.80-r0 | < 6.12.77-r2

  • chainguardlinux-qemu-6.12

    < 6.12.80-r0 | < 6.12.78-r0 | < 6.12.77-r1 | < 6.12.77-r2

  • chainguardlinux-vmware-6.12

    < 6.12.77-r1 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.78-r0

  • debianlinux

    < 6.12.85-1 | < 6.18.10-1

  • ubuntulinux

    all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.14

    all

  • ubuntulinux-aws-6.17

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-azure

    all | all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.14

    all

  • ubuntulinux-azure-6.17

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.14

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-nvidia-6.14

    all

  • ubuntulinux-bluefield

    all

  • ubuntulinux-gcp

    all | all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.11

    all

  • ubuntulinux-gcp-6.14

    all

  • ubuntulinux-gcp-6.17

    all

  • ubuntulinux-gcp-6.2

    all

  • ubuntulinux-gcp-6.5

    all

  • ubuntulinux-gke

    all

  • ubuntulinux-gke-4.15

    all

Showing first 50 affected entries in server-rendered view.

References (7)