CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's gve component, specifically related to a NULL pointer dereference that can be exploited through user-mode applications. This flaw can lead to system crashes or instability when the `adjfine` function is improperly invoked, particularly using the `testptp` command. Organizations utilizing Linux systems, especially those relying on precise time synchronization features, should prioritize addressing this vulnerability to maintain system reliability and security.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: gve: fix NULL dereference due to missing ptp adjfine Fix NULL dereference due to missing implementation of adjfine, which can be triggered from usermode as follows: sudo ./testptp -d /dev/ptp0 -f 0 [ 551.943697] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] [ 552.061946] Call Trace: [ 552.064487] <TASK> [ 552.066681] ptp_clock_adjtime+0x1c0/0x2c0 [ 552.070874] ? get_clock_desc+0x6b/0xb0 [ 552.074825] pc_clock_adjtime+0x78/0xc0 [ 552.078755] __do_sys_clock_adjtime+0x85/0x110 [ 552.083293] do_syscall_64+0xea/0x610