Wind River Support Network

HomeDefectsLIN1023-13752
Acknowledged

LIN1023-13752 : Security Advisory - linux - CVE-2025-38126

Created: Jul 3, 2025    Updated: Jul 8, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:EOL][EOL]net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping[EOL][EOL]The stmmac platform drivers that do not open-code the clk_ptp_rate value[EOL]after having retrieved the default one from the device-tree can end up[EOL]with 0 in clk_ptp_rate (as clk_get_rate can return 0). It will[EOL]eventually propagate up to PTP initialization when bringing up the[EOL]interface, leading to a divide by 0:[EOL][EOL] Division by zero in kernel.[EOL] CPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.30-00001-g48313bd5768a #22[EOL] Hardware name: STM32 (Device Tree Support)[EOL] Call trace:[EOL]  unwind_backtrace from show_stack+0x18/0x1c[EOL]  show_stack from dump_stack_lvl+0x6c/0x8c[EOL]  dump_stack_lvl from Ldiv0_64+0x8/0x18[EOL]  Ldiv0_64 from stmmac_init_tstamp_counter+0x190/0x1a4[EOL]  stmmac_init_tstamp_counter from stmmac_hw_setup+0xc1c/0x111c[EOL]  stmmac_hw_setup from __stmmac_open+0x18c/0x434[EOL]  __stmmac_open from stmmac_open+0x3c/0xbc[EOL]  stmmac_open from __dev_open+0xf4/0x1ac[EOL]  __dev_open from __dev_change_flags+0x1cc/0x224[EOL]  __dev_change_flags from dev_change_flags+0x24/0x60[EOL]  dev_change_flags from ip_auto_config+0x2e8/0x11a0[EOL]  ip_auto_config from do_one_initcall+0x84/0x33c[EOL]  do_one_initcall from kernel_init_freeable+0x1b8/0x214[EOL]  kernel_init_freeable from kernel_init+0x24/0x140[EOL]  kernel_init from ret_from_fork+0x14/0x28[EOL] Exception stack(0xe0815fb0 to 0xe0815ff8)[EOL][EOL]Prevent this division by 0 by adding an explicit check and error log[EOL]about the actual issue. While at it, remove the same check from[EOL]stmmac_ptp_register, which then becomes duplicate

CREATE(Triage):(User=lchen-cn) [CVE-2025-38126 (https://nvd.nist.gov/vuln/detail/CVE-2025-38126)
Live chat
Online