In the Linux kernel, the following vulnerability has been resolved:
ice: Don't process extts if PTP is disabled
The iceptpexttsevent() function can race with iceptp_release() and result in a NULL pointer dereference which leads to a kernel panic.
Panic occurs because the iceptpexttsevent() function calls ptpclock_event() with a NULL pointer. The ice driver has already released the PTP clock by the time the interrupt for the next external timestamp event occurs.
To fix this, modify the iceptpextts_event() function to check the PTP state and bail early if PTP is not ready.