---
id: CVE-2026-90100
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ptp: netc: fix period truncation and potential divide-by-zero in PEROUT

  The max_period bound in net_timer_enable_perout() was computed as:

    max_period = (u64)NETC_TM…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ptp: netc: fix period truncation and potential divide-by-zero in PEROUT

  The max_period bound in net_timer_enable_perout() was computed as:

    max_period = (u64)NETC_TM…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 671e266835b8a87d6cc2c6db962de23783405dd8 <
    51fe3fe0ffec033bd831c71d9bee3dee827e491c
  - >-
    Linux >= 671e266835b8a87d6cc2c6db962de23783405dd8 <
    08988d1941e180f0ad30d91233cb64f3418ba23c
  - >-
    Linux >= 671e266835b8a87d6cc2c6db962de23783405dd8 <
    777dbc9914b2f003f1d44af80c7a4a395c5961b2
  - Linux 6.18
published: '2026-09-17'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T17:17:01.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90100'
references:
  - url: 'https://git.kernel.org/stable/c/08988d1941e180f0ad30d91233cb64f3418ba23c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/51fe3fe0ffec033bd831c71d9bee3dee827e491c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/777dbc9914b2f003f1d44af80c7a4a395c5961b2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-17T16:21:47.890Z'
epss: 0.00198
epssPercentile: 0.09821
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ptp: netc: fix period truncation and potential divide-by-zero in PEROUT

The max_period bound in net_timer_enable_perout() was computed as:

  max_period = (u64)NETC_TMR_DEFAULT_FIPER + integral_period;

which exceeds U32_MAX when integral_period > 0 (e.g. 0x100000002 for
the default 333333333 Hz clock). A period_ns that passes this check but
exceeds U32_MAX is then silently truncated when stored into the u32
struct netc_pp::period field.

A truncated value of zero can reach netc_timer_set_perout_alarm(), where
the local u32 period variable would also be 0, causing a divide-by-zero
in roundup_u64(delta, period) whenever the stime < min_time branch is
taken (which always happens for a start time of {0, 0}).

Additionally, netc_timer_enable_periodic_pulse() and
netc_timer_enable_fiper() both compute:

  fiper = pp->period - integral_period;

A zero pp->period results in an unsigned wraparound to 0xFFFFFFFD,
mis-programming the FIPER hardware register.

Fix all three issues by capping max_period at NETC_TMR_DEFAULT_FIPER
(0xFFFFFFFF). This ensures that any period_ns passing the range check
fits in a u32 without truncation, so the stored value is always valid
and non-zero. The accepted range is reduced by integral_period ns
(typically only a few nanoseconds), which is negligible in practice.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
