NULL pointer dereference in Linux kernel - CVE-2026-43173
Published: May 7, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in ixp4xx_get_ts_info() when handling ethtool timestamp information requests. A local user can invoke the affected ioctl path to cause a denial of service.
The issue occurs on systems where the driver calls ixp46x_ptp_find() without properly verifying PTP support.
How to mitigate CVE-2026-43173
Sources
- https://git.kernel.org/stable/c/144dde3146985b25fa84d4e4b7c3d11e0f5fc5a4
- https://git.kernel.org/stable/c/21d1e80d0d6e7d0c3cd8b1e001ed1fa92fb9f3f5
- https://git.kernel.org/stable/c/2d74412dfd3621552a394d55cc3dd26a7cbf608e
- https://git.kernel.org/stable/c/322437972f0a712767f6920ad34aba25f2e9b942
- https://git.kernel.org/stable/c/5195b10c34b8993194ad12ad7d8f54d861be084b
- https://git.kernel.org/stable/c/594163ea88a03bdb412063af50fc7177ef3cbeae
- https://git.kernel.org/stable/c/cbecebd35909f6cd0f6fb773f0fb73da99e02f8c