CVE-2026-68133 PUBLISHED

ice: fix PTP Call Trace during PTP release

Assigner: Linux
Reserved: 30.07.2026 Published: 10.08.2026 Updated: 10.08.2026

In the Linux kernel, the following vulnerability has been resolved:

ice: fix PTP Call Trace during PTP release

If a PF reset occurs when the PTP state is ICE_PTP_UNINIT, then ice_ptp_rebuild() will update the state to ICE_PTP_ERROR. This will result in the following PTP release call trace during driver unload:

<pre>kernel BUG at lib/list_debug.c:52! ice_ptp_release+0x332/0x3c0 [ice] ice_deinit_features.part.0+0x10e/0x120 [ice] ice_remove+0x100/0x220 [ice] </pre>

This was observed when passing PF1 through to a VM. ice_ptp_init() fails because ctrl_pf is NULL and sets the state to ICE_PTP_UNINIT.

Fix by detecting the ICE_PTP_UNINIT state in ice_ptp_rebuild() and returning without error, preventing the invalid state transition to ICE_PTP_ERROR. The only valid path to ICE_PTP_ERROR is from ICE_PTP_RESETTING after a failed rebuild.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 to 7d517b255f669cedd09830214d55f2f413b34481 (excl.)
  • affected from 8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 to e4406cbdd915f702d2ed9ee8b30683a16b06c6ac (excl.)
  • affected from 8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 to 14fceda28069fdbe1bb49cdb6e1774892b583348 (excl.)
  • affected from 8293e4cb2ff54b1ec4f7206dcb74c908f62a3fb8 to f6a7e00b81e35ef1325234925f2fe1e53b466f92 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.9 is affected
  • unaffected from 0 to 6.9 (excl.)
  • unaffected from 6.12.101 to 6.12.* (incl.)
  • unaffected from 6.18.42 to 6.18.* (incl.)
  • unaffected from 7.1.6 to 7.1.* (incl.)
  • unaffected from 7.2-rc5 to * (incl.)

References