iavf: Implement settime64 with -EOPNOTSUPP
Published Jan 5, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.18%
Description
ptp_clock_settime() assumes every ptp_clock has implemented settime64(). Stub it with -EOPNOTSUPP to prevent a NULL dereference.
The fix is similar to commit 329d050bbe63 ("gve: Implement settime64 with -EOPNOTSUPP").
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.15
- Version 6.17.13StatusunaffectedConstraints<=6.17.*
- Version 6.18.2StatusunaffectedConstraints<=6.18.*
- Version 6.19StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Enterprise Linux 10
kernel
Fix deferred
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Fix deferred
Red Hat Enterprise Linux 9
kernel-rt
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability requires local access and the ability to interact with PTP clock devices. Exploitation leads to a kernel panic but does not allow code execution or data compromise. Systems using iavf virtual network adapters in virtualized environments with PTP enabled are affected.
Red Hat mitigation
To mitigate this issue, prevent the iavf module from being loaded if Intel Adaptive Virtual Function network devices are not required. See https://access.redhat.com/solutions/41278 for instructions on how to blacklist a kernel module.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-68752 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2427126 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-0894 Advisory
- https://git.kernel.org/stable/c/1e43ebcd5152b3e681a334cc6542fb21770c3a2e
- https://git.kernel.org/stable/c/6d080f810ffd6b8e002ce5bee8b9c551ca2535c2
- https://git.kernel.org/stable/c/9e3dbc3bb2e2aa728b49422b2e5344488f93f690
- https://lore.kernel.org/linux-cve-announce/2026010548-CVE-2025-68752-b0e7@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-68752
- https://www.cve.org/CVERecord?id=CVE-2025-68752
Change history (0)
No recorded changes yet.