PT-2026-90057 · Linux · Linux

CVE-2026-80927

·

Published

2026-09-11

·

Updated

2026-09-11

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
timekeeping: Check the return value of tk get aux ts64 in do adjtimex()
If the auxiliary clock is disabled during tk get aux ts64() but is enabled before tks->clock valid is checked, then uninitialized stackdata will be used in the calculations and indirectly leaked to userspace.
The same race window also exists after this change and also for the core timekeeper. But in these cases the only effect would be incorrect adjustments and this is userspace's responsibility to avoid this.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80927

Affected Products

Linux