CVE-2026-53222 PUBLISHED

ptp: ocp: fix resource freeing order

Assigner: Linux
Reserved: 09.06.2026 Published: 25.06.2026 Updated: 25.06.2026

In the Linux kernel, the following vulnerability has been resolved:

ptp: ocp: fix resource freeing order

Commit a60fc3294a37 ("ptp: rework ptp_clock_unregister() to disable events") added a call to ptp_disable_all_events() which changes the configuration of pins if they support EXTTS events. In ptp_ocp_detach() pins resources are freed before ptp_clock_unregister() and it leads to use-after-free during driver removal. Fix it by changing the order of free/unregister calls. To avoid irq handler running on the other core while ptp device unregistering, call synchronize_irq() after HW is configured to stop producing irqs and no irqs are in-flight.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a60fc3294a377204664b5484e4a487fa124155da to aa03698bb28d3be5ee180adb185395054b342b04 (excl.)
  • affected from a60fc3294a377204664b5484e4a487fa124155da to 627366c51145a07f675b1800fb5ea2ec960bd900 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.18 is affected
  • unaffected from 0 to 6.18 (excl.)
  • unaffected from 7.0.13 to 7.0.* (incl.)
  • unaffected from 7.1 to * (incl.)

References