In the Linux kernel, the following vulnerability has been resolved:
ice: fix race condition in TX timestamp ring cleanup
Fix a race condition between icefreetxtstampring() and icetxmap() that can cause a NULL pointer dereference.
icefreetxtstampring currently clears the ICETXFLAGSTXTIME flag after NULLing the tstampring. This could allow a concurrent icetxmap call on another CPU to dereference the tstamp_ring, which could lead to a NULL pointer dereference.
CPU A:icefreetxtstampring() | CPU B:icetxmap() --------------------------------|--------------------------------- txring->tstampring = NULL | | iceistxtimecfg() -> true | tstampring = txring->tstampring | tstampring->count // NULL deref! flags &= ~ICETXFLAGSTXTIME |
Fix by: 1. Reordering icefreetxtstampring() to clear the flag before NULLing the pointer, with smpwmb() to ensure proper ordering. 2. Adding smprmb() in icetxmap() after the flag check to order the flag read before the pointer read, using READONCE() for the pointer, and adding a NULL check as a safety net. 3. Converting txring->flags from u8 to DECLAREBITMAP() and using atomic bitops (setbit(), clearbit(), testbit()) for all flag operations throughout the driver: - ICETXRINGFLAGSXDP - ICETXRINGFLAGSVLANL2TAG1 - ICETXRINGFLAGSVLANL2TAG2 - ICETXRINGFLAGSTXTIME
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/53xxx/CVE-2026-53008.json"
}