← All Advisories

Linux Kernel Uses the jiffies Clocksource Before It Is Registered With the Clocksource Framework, Causing XEN HVM Guests to Experience Long Boot Delays Due to Negative Motion Reporting

Last refreshed2026-09-28

Status: NEW  |  Advisory ID: CVE-2026-68092

Key Details

CVECVE-2026-68092

What to Know

In the Linux kernel, the following vulnerability has been resolved:

time/jiffies: Register jiffies clocksource before usage

Teddy reported that a XEN HVM has a long boot delay, which was bisected to

the recent enhancements to the negative motion detection. It turned out

that the jiffies clocksource is used in early boot before it is registered,

which leaves the max_delta_raw field at zero. That causes the read out to

be clamped to the max delta of 0, which means time is not making progress.

Cure it by ensuring that it is initialized before its first usage in

timekeeping_init(). (NVD)

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-68092
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-68092