From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0FA3A552947 for ; Fri, 11 Sep 2026 19:47:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156041; cv=none; b=S3V0EaFge9gMxVEfAhXzUPFNo5ymrRS/F50DHEZYj3ByCTmmUYGnyr4ntBBNkSyi1b0vJemH+MByDsr/HloZfMWoGNmkcEDLrXJ0EZ/XMURb6QJXR6crNTWWWwUHyfnYnTxn9LWgXYP6TDPDvcHofQCsTjchd7qISoRUHp1VGr4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156041; c=relaxed/simple; bh=C2Z8cQPo/9aPL/ArMWm1HhOq+cEgDNtyJctDe1pRMRo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=WdstU918PBJZ9Ul4iO+TX8XOV2LDD4nOSddT7SEXtUF6fFWG4Ic46RhFKr5rxWryF1f5eFt0zevVmRcWj56X9bBeyP+EYK47x8PaVvACARpqp10ThvVkOLEdkEdTvNLSLZnvwrFwocWvBzV3V0XNiEQ9wZGmQFqiY01UldWwRjI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=0X0bT3wA; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="0X0bT3wA" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 639B81F00893; Fri, 11 Sep 2026 19:47:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156022; bh=N0oHiBQ8JO5L1y96wr1sTH+w3ZEwgtVLMIGLjiEHjdQ=; h=From:To:Cc:Subject:Date:Reply-To; b=0X0bT3wAThJ6U29XzqfPzBmytrmIo0hfiveTEOrLnTMHSp59gMxWKEJC99N75GCjn pAEUVsaDNWXQTgU5IgI661KTtRnIP3X7LV0b4rQtUd2lEja1nirFIzJQ06hJxF1wst +bPypKEBNG3BAAaOPqo/6yQNtpXb+QG3HrMF/B+w= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80927: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() Date: Fri, 11 Sep 2026 21:40:33 +0200 Message-ID: <2026091134-CVE-2026-80927-36dc@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2433; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=vM6qWrb11Cr6w/0z8wK9+vcsceGevgiOQy0YqFCPucY=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIo2u9oVcV6jfy8/lf/oKX+xMzkdr3xq/7l60rtZES rPTaMe7jlgWBkEmBlkxRZYv23iO7q84pOhlaHsaZg4rE8gQBi5OAZjIqVcMc4V3r5qvIyuzXUDy aLbQhPkmhy/NKWJYcDT4iHXzBvbdpjaW73xMDF/N5mllAAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: timekeeping: Check the return value of tk_get_aux_ts64 in __do_adjtimex() If the auxiliary clock is disabled during tk_get_aux_ts64() but is enabled before tks->clock_valid is checked, then uninitialized stackdata will be used in the calculations and indirectly leaked to userspace. The same race window also exists after this change and also for the core timekeeper. But in these cases the only effect would be incorrect adjustments and this is userspace's responsibility to avoid this. The Linux kernel CVE team has assigned CVE-2026-80927 to this issue. Affected and fixed versions =========================== Issue introduced in 6.17 with commit 4eca49d0b621b314ac7c80f363932ec6f6c8abc8 and fixed in 6.18.50 with commit fecf1e37775269ad38c172b468ad4ecc3968aa63 Issue introduced in 6.17 with commit 4eca49d0b621b314ac7c80f363932ec6f6c8abc8 and fixed in 7.2.4 with commit bc59dac50cb45a725f7a50760c7cc72a0964f722 Issue introduced in 6.17 with commit 4eca49d0b621b314ac7c80f363932ec6f6c8abc8 and fixed in 7.3-rc1 with commit 4b61084b11bcecce86d03804ff30f8d7b465593c Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80927 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: kernel/time/timekeeping.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/fecf1e37775269ad38c172b468ad4ecc3968aa63 https://git.kernel.org/stable/c/bc59dac50cb45a725f7a50760c7cc72a0964f722 https://git.kernel.org/stable/c/4b61084b11bcecce86d03804ff30f8d7b465593c