CVE-2026-80866 (GCVE-0-2026-80866)

Vulnerability from cvelistv5 – Published: 2026-09-04 16:48 – Updated: 2026-09-04 16:48
VLAI
Title
tipc: avoid busy looping in tipc_exit_net()
Summary
In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete: while (atomic_read(&tn->wq_count)) cond_resched(); This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups. Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero. Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero. This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.
Severity
No CVSS data available.
Impacted products
Vendor Product Version
Linux Linux Affected: 04c26faa51d1e2fe71cf13c45791f5174c37f986 , < 522d1d950b9e3b68190a6de7534827c8dccedb73 (git)
Affected: 04c26faa51d1e2fe71cf13c45791f5174c37f986 , < c1481c94e74c955e0448ddf46b8615a44d840c1e (git)
Affected: d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa (git)
Affected: 5195ec5e365a2a9331bfeb585b613a6e94f98dba (git)
Affected: b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d (git)
Affected: 5.4.124 , < 5.5 (semver)
Affected: 5.10.42 , < 5.11 (semver)
Affected: 5.12.9 , < 5.13 (semver)
Create a notification for this product.
Linux Linux Affected: 5.13
Unaffected: 0 , < 5.13 (semver)
Unaffected: 7.1.5 , ≤ 7.1.* (semver)
Unaffected: 7.2 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/tipc/core.c",
            "net/tipc/udp_media.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "522d1d950b9e3b68190a6de7534827c8dccedb73",
              "status": "affected",
              "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
              "versionType": "git"
            },
            {
              "lessThan": "c1481c94e74c955e0448ddf46b8615a44d840c1e",
              "status": "affected",
              "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5195ec5e365a2a9331bfeb585b613a6e94f98dba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d",
              "versionType": "git"
            },
            {
              "lessThan": "5.5",
              "status": "affected",
              "version": "5.4.124",
              "versionType": "semver"
            },
            {
              "lessThan": "5.11",
              "status": "affected",
              "version": "5.10.42",
              "versionType": "semver"
            },
            {
              "lessThan": "5.13",
              "status": "affected",
              "version": "5.12.9",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/tipc/core.c",
            "net/tipc/udp_media.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "lessThan": "5.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.5",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.4.124",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.10.42",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "5.12.9",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(\u0026tn-\u003ewq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed."
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-04T16:48:11.682Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73"
        },
        {
          "url": "https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e"
        }
      ],
      "title": "tipc: avoid busy looping in tipc_exit_net()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-80866",
    "datePublished": "2026-09-04T16:48:11.682Z",
    "dateReserved": "2026-08-26T14:34:25.798Z",
    "dateUpdated": "2026-09-04T16:48:11.682Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-80866",
      "date": "2026-10-03",
      "epss": "0.00198",
      "percentile": "0.08651"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "net/tipc/core.c",
                  "net/tipc/udp_media.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "522d1d950b9e3b68190a6de7534827c8dccedb73",
                    "status": "affected",
                    "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "c1481c94e74c955e0448ddf46b8615a44d840c1e",
                    "status": "affected",
                    "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "5195ec5e365a2a9331bfeb585b613a6e94f98dba",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "5.5",
                    "status": "affected",
                    "version": "5.4.124",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.11",
                    "status": "affected",
                    "version": "5.10.42",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "5.13",
                    "status": "affected",
                    "version": "5.12.9",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "net/tipc/core.c",
                  "net/tipc/udp_media.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "5.13"
                  },
                  {
                    "lessThan": "5.13",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.1.*",
                    "status": "unaffected",
                    "version": "7.1.5",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.2",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(\u0026tn-\u003ewq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed."
          }
        ],
        "id": "CVE-2026-80866",
        "lastModified": "2026-09-04T17:16:58.390",
        "metrics": {},
        "published": "2026-09-04T17:16:58.390",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…