In the Linux kernel, the following vulnerability has been resolved:
ice: prevent tstamp ring allocation for non-PF VSI types
The pf->txtimetxqs bitmap tracks which Tx queues have ETF (Earliest TxTime First) offload enabled. This bitmap is indexed by queue number and is set by iceoffload_txtime(), which only operates on PF VSI queues.
However, iceistxtimeena() does not check the VSI type before consulting the bitmap. When ETF offload is enabled on PF Tx queue 0, bit 0 is set in pf->txtimetxqs. During a subsequent PCI reset rebuild, the CTRL VSI's Tx queue 0 is reconfigured and iceistxtimeena() is called for that ring. Since it only checks pf->txtimetxqs by queue index without distinguishing VSI type, it finds bit 0 set and returns true, matching the PF VSI's ETF queue, not the CTRL VSI's. This causes icevsicfgtxq() to spuriously allocate a tstampring for the CTRL VSI ring.
Since CTRL VSI rings have no associated netdev, icecleantxring() takes an early return at the !netdev check before reaching icefreetxtstampring(), leaking the allocation. Each PCI reset leaks one 64-byte tstampring.
Fix this by restricting iceistxtimeena() to return true only for PF VSI rings, since txtimetxqs is only meaningful for PF VSI queues.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68292.json",
"cna_assigner": "Linux"
}