Action not permitted
Modal body text goes here.
Modal Title
Modal Body
WID-SEC-W-2026-3294
Vulnerability from csaf_certbund - Published: 2026-09-09 22:00 - Updated: 2026-09-29 22:00Summary
Linux Kernel: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: Der Kernel stellt den Kern des Linux Betriebssystems dar.
Angriff: Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.
Betroffene Betriebssysteme: - Linux
Affected products
Known affected
3 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Debian Linux
Debian
|
cpe:/o:debian:debian_linux:-
|
— | |
|
Amazon Linux 2
Amazon
|
cpe:/o:amazon:linux_2:-
|
— | |
|
Open Source Linux Kernel
Open Source
|
cpe:/o:linux:linux_kernel:-
|
— |
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
Affected products
Known affected
3 products, the same list as for
CVE-2026-80914
References
18 references
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "Der Kernel stellt den Kern des Linux Betriebssystems dar.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsma\u00dfnahmen zu umgehen, sensible Informationen offenzulegen, Daten zu manipulieren, Denial-of-Service-Zust\u00e4nde herbeizuf\u00fchren oder andere, nicht n\u00e4her spezifizierte Angriffe durchzuf\u00fchren.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Linux",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-3294 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-3294.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-3294 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3294"
},
{
"category": "external",
"summary": "Kernel CVE Announce Mailingliste",
"url": "https://lore.kernel.org/linux-cve-announce/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80914",
"url": "https://lore.kernel.org/linux-cve-announce/2026090900-CVE-2026-80914-7e1f@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80915",
"url": "https://lore.kernel.org/linux-cve-announce/2026090914-CVE-2026-80915-0665@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80916",
"url": "https://lore.kernel.org/linux-cve-announce/2026090914-CVE-2026-80916-00ed@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80917",
"url": "https://lore.kernel.org/linux-cve-announce/2026090915-CVE-2026-80917-c530@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80918",
"url": "https://lore.kernel.org/linux-cve-announce/2026090915-CVE-2026-80918-41ce@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80919",
"url": "https://lore.kernel.org/linux-cve-announce/2026090915-CVE-2026-80919-6fae@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80920",
"url": "https://lore.kernel.org/linux-cve-announce/2026090915-CVE-2026-80920-9c6d@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80921",
"url": "https://lore.kernel.org/linux-cve-announce/2026090942-CVE-2026-80921-0e26@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80922",
"url": "https://lore.kernel.org/linux-cve-announce/2026090942-CVE-2026-80922-a96a@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80923",
"url": "https://lore.kernel.org/linux-cve-announce/2026090943-CVE-2026-80923-3fb0@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80924",
"url": "https://lore.kernel.org/linux-cve-announce/2026090943-CVE-2026-80924-063f@gregkh/"
},
{
"category": "external",
"summary": "Linux Kernel CVE Announcement CVE-2026-80925",
"url": "https://lore.kernel.org/linux-cve-announce/2026090943-CVE-2026-80925-d4f2@gregkh/"
},
{
"category": "external",
"summary": "Debian Security Advisory DLA-4788 vom 2026-09-19",
"url": "https://lists.debian.org/debian-lts-announce/2026/09/msg00023.html"
},
{
"category": "external",
"summary": "Amazon Linux Security Advisory ALAS2KERNEL-5.10-2026-132 vom 2026-09-29",
"url": "https://alas.aws.amazon.com/AL2/ALAS2KERNEL-5.10-2026-132.html"
},
{
"category": "external",
"summary": "Debian Security Advisory DSA-6528 vom 2026-09-29",
"url": "https://security-tracker.debian.org/tracker/DSA-6528-1"
}
],
"source_lang": "en-US",
"title": "Linux Kernel: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-09-29T22:00:00.000+00:00",
"generator": {
"date": "2026-09-30T10:09:59.982+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-3294",
"initial_release_date": "2026-09-09T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-09-09T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
},
{
"date": "2026-09-20T22:00:00.000+00:00",
"number": "2",
"summary": "Neue Updates von Debian aufgenommen"
},
{
"date": "2026-09-28T22:00:00.000+00:00",
"number": "3",
"summary": "Neue Updates von Amazon aufgenommen"
},
{
"date": "2026-09-29T22:00:00.000+00:00",
"number": "4",
"summary": "Neue Updates von Debian aufgenommen"
}
],
"status": "final",
"version": "4"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "Amazon Linux 2",
"product": {
"name": "Amazon Linux 2",
"product_id": "398363",
"product_identification_helper": {
"cpe": "cpe:/o:amazon:linux_2:-"
}
}
}
],
"category": "vendor",
"name": "Amazon"
},
{
"branches": [
{
"category": "product_name",
"name": "Debian Linux",
"product": {
"name": "Debian Linux",
"product_id": "2951",
"product_identification_helper": {
"cpe": "cpe:/o:debian:debian_linux:-"
}
}
}
],
"category": "vendor",
"name": "Debian"
},
{
"branches": [
{
"category": "product_name",
"name": "Open Source Linux Kernel",
"product": {
"name": "Open Source Linux Kernel",
"product_id": "T059366",
"product_identification_helper": {
"cpe": "cpe:/o:linux:linux_kernel:-"
}
}
}
],
"category": "vendor",
"name": "Open Source"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-80914",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80914"
},
{
"cve": "CVE-2026-80915",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80915"
},
{
"cve": "CVE-2026-80916",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80916"
},
{
"cve": "CVE-2026-80917",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80917"
},
{
"cve": "CVE-2026-80918",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80918"
},
{
"cve": "CVE-2026-80919",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80919"
},
{
"cve": "CVE-2026-80920",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80920"
},
{
"cve": "CVE-2026-80921",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80921"
},
{
"cve": "CVE-2026-80922",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80922"
},
{
"cve": "CVE-2026-80923",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80923"
},
{
"cve": "CVE-2026-80924",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80924"
},
{
"cve": "CVE-2026-80925",
"product_status": {
"known_affected": [
"2951",
"398363",
"T059366"
]
},
"release_date": "2026-09-09T22:00:00.000+00:00",
"title": "CVE-2026-80925"
}
]
}
CVE-2026-80914 (GCVE-0-2026-80914)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:10 – Updated: 2026-09-14 11:58
VLAI
EPSS
VEX
Title
Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
Summary
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready
iso_conn_ready() looks up the BIS listener socket with iso_get_sock(),
which takes a reference, and then, without re-checking its state,
creates a child socket from it:
parent = iso_get_sock(hdev, ...);
if (!parent)
return;
lock_sock(parent);
sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...);
...
iso_chan_add(conn, sk, parent);
...
release_sock(parent);
sock_put(parent);
If the listener socket is closed concurrently, between iso_get_sock()
and lock_sock(), the reference taken by iso_get_sock() may be the last
one: the close path drops the link-list reference, and once
iso_conn_ready() drops its own reference at the end of the function the
socket is freed. The child socket, however, is already linked to the
freed parent, and a later disconnect of the child runs iso_chan_del()
-> bt_accept_unlink(), which dereferences the dangling parent pointer
into the freed accept queue (a use-after-free). The same dangling
pointer is also dereferenced through parent->***() in
iso_chan_del().
Fix it the same way the connected (non-BIS) path was fixed in commit
0d255e63fcf3 ("Bluetooth: ISO: hold sk properly in iso_conn_ready"):
after taking the socket lock, re-check that the parent is still a
listening, alive socket, and bail out otherwise.
Severity
8.8 (High)
Assigner
References
6 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
ccf74f2390d60a2f9a75ef496d2564abb478f46a , < 1702f12cf59a1c3b670eb6bb4a4d6fcccf07e3b8
(git)
Affected: ccf74f2390d60a2f9a75ef496d2564abb478f46a , < d47b8f8c02a3d3f282693e5a4ff1f6b4b00518de (git) Affected: ccf74f2390d60a2f9a75ef496d2564abb478f46a , < 2387cd06a2c0b416f05028b02bba1089f54c28d9 (git) Affected: ccf74f2390d60a2f9a75ef496d2564abb478f46a , < 49fd7116f76b860b230843700fb7423ab5331e1f (git) Affected: ccf74f2390d60a2f9a75ef496d2564abb478f46a , < 03288b7447c9e572f8ab82fc29cfb4ca719ab210 (git) Affected: ccf74f2390d60a2f9a75ef496d2564abb478f46a , < 560bef609fa5992745929e8d7d458b9d88dd2830 (git) |
|
| Linux | Linux |
Affected:
6.0
Unaffected: 0 , < 6.0 (semver) Unaffected: 6.1.188 , ≤ 6.1.* (semver) Unaffected: 6.6.157 , ≤ 6.6.* (semver) Unaffected: 6.12.109 , ≤ 6.12.* (semver) Unaffected: 6.18.50 , ≤ 6.18.* (semver) Unaffected: 7.2.4 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "1702f12cf59a1c3b670eb6bb4a4d6fcccf07e3b8",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "d47b8f8c02a3d3f282693e5a4ff1f6b4b00518de",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "2387cd06a2c0b416f05028b02bba1089f54c28d9",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "49fd7116f76b860b230843700fb7423ab5331e1f",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "03288b7447c9e572f8ab82fc29cfb4ca719ab210",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
},
{
"lessThan": "560bef609fa5992745929e8d7d458b9d88dd2830",
"status": "affected",
"version": "ccf74f2390d60a2f9a75ef496d2564abb478f46a",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/bluetooth/iso.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.0"
},
{
"lessThan": "6.0",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.188",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.157",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.109",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.50",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.4",
"versionStartIncluding": "6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready\n\niso_conn_ready() looks up the BIS listener socket with iso_get_sock(),\nwhich takes a reference, and then, without re-checking its state,\ncreates a child socket from it:\n\n parent = iso_get_sock(hdev, ...);\n if (!parent)\n return;\n\n lock_sock(parent);\n sk = iso_sock_alloc(sock_net(parent), NULL, BTPROTO_ISO, ...);\n ...\n iso_chan_add(conn, sk, parent);\n ...\n release_sock(parent);\n sock_put(parent);\n\nIf the listener socket is closed concurrently, between iso_get_sock()\nand lock_sock(), the reference taken by iso_get_sock() may be the last\none: the close path drops the link-list reference, and once\niso_conn_ready() drops its own reference at the end of the function the\nsocket is freed. The child socket, however, is already linked to the\nfreed parent, and a later disconnect of the child runs iso_chan_del()\n-\u003e bt_accept_unlink(), which dereferences the dangling parent pointer\ninto the freed accept queue (a use-after-free). The same dangling\npointer is also dereferenced through parent-\u003e***() in\niso_chan_del().\n\nFix it the same way the connected (non-BIS) path was fixed in commit\n0d255e63fcf3 (\"Bluetooth: ISO: hold sk properly in iso_conn_ready\"):\nafter taking the socket lock, re-check that the parent is still a\nlistening, alive socket, and bail out otherwise."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:A - The UAF is in Bluetooth ISO iso_conn_ready() parent-lookup for incoming CIS/BIS/PA; that path runs from HCI connect_cfm events (hci_le_cis_req_evt, BIG/PA sync) driven by LE isochronous traffic from peers in radio range, which is an adjacent attack surface.\nAC:L - This is a use-after-free race between iso_get_sock() and listener close (iso_sock_release/iso_sock_kill) before lock_sock(); an attacker who opens/closes an ISO listen socket while concurrent HCI CIS/BIS/PA completion runs controls both sides and can trigger it without uncontrollable conditions.\nPR:N - iso_sock_create has no capability check, and the vulnerable path is reached from unauthenticated HCI CIS/BIG/PA events processed for any Bluetooth-enabled device in range; listener close can occur from automatic LE Audio/bluetoothd teardown without privileged local credentials.\nUI:N - No victim action is required: iso_connect_ind returns HCI_LM_ACCEPT so incoming CIS/BIS/PA sync is auto-accepted when an ISO listener exists, and OS LE Audio stacks keep such listeners during normal broadcast/unicast operation.\nS:U - The UAF corrupts kernel socket/accept-queue memory and can enable privilege escalation within the host kernel; it does not cross a VM, container, or IOMMU security boundary, so scope remains unchanged.\nC:H - Use-after-free of the listener struct sock (and later bt_accept_unlink of the dangling parent) lets an attacker reuse the freed sock/accept-queue object, enabling arbitrary kernel memory disclosure via heap grooming per UAF guidance.\nI:H - The child is linked to the freed parent via iso_chan_add/bt_accept_enqueue; later iso_chan_del -\u003e bt_accept_unlink writes the freed parent\u0027s accept queue (list_del, sk_acceptq_removed), a kernel heap write primitive usable for control-flow hijack.\nA:H - Dereferencing the freed listener in iso_chan_del/bt_accept_unlink (accept_q_lock, list, parent-\u003esk_data_ready) causes kernel oops/panic; UAFs in this ISO path are a high availability impact even before full exploitation."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T11:58:54.701Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/1702f12cf59a1c3b670eb6bb4a4d6fcccf07e3b8"
},
{
"url": "https://git.kernel.org/stable/c/d47b8f8c02a3d3f282693e5a4ff1f6b4b00518de"
},
{
"url": "https://git.kernel.org/stable/c/2387cd06a2c0b416f05028b02bba1089f54c28d9"
},
{
"url": "https://git.kernel.org/stable/c/49fd7116f76b860b230843700fb7423ab5331e1f"
},
{
"url": "https://git.kernel.org/stable/c/03288b7447c9e572f8ab82fc29cfb4ca719ab210"
},
{
"url": "https://git.kernel.org/stable/c/560bef609fa5992745929e8d7d458b9d88dd2830"
}
],
"title": "Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80914",
"datePublished": "2026-09-09T16:10:58.675Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-14T11:58:54.701Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80915 (GCVE-0-2026-80915)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
drm/xe: Fix DPT allocation paths.
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Fix DPT allocation paths.
Remove the fallback for VRAM to system memory, I tested it and that
doesn't work at all, only a black screen with pipe fault errors were
observed.
On systems with media GT, extra latency is added when accessing stolen
memory when the GT is in MC6. Since we additionally aren't counting how
much memory is used for stolen and we could in theory fill up the
entire stolen area with DPT's, avoid using stolen and only use the
default memory region.
Using stolen may also result in random system hangs under load.
(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)
Severity
No CVSS data available.
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
775d0adc01a55fe0458139330415d86bb3533efe , < 491c499295fb0b90308b230b0a1075dcdf7f4d12
(git)
Affected: 775d0adc01a55fe0458139330415d86bb3533efe , < f03415030579163f791c978741af7f1f2f6510b7 (git) Affected: 775d0adc01a55fe0458139330415d86bb3533efe , < c457e2c845ccbf2224386029f3da4937ba424db0 (git) Affected: 775d0adc01a55fe0458139330415d86bb3533efe , < fc648757908304aedbad74f74bf58192aec383db (git) Affected: 4854ac2f88e2168ee4da2b152c6711772a8149aa (git) Affected: 6.11.3 , < 6.12 (semver) |
|
| Linux | Linux |
Affected:
6.12
Unaffected: 0 , < 6.12 (semver) Unaffected: 6.12.106 , ≤ 6.12.* (semver) Unaffected: 6.18.47 , ≤ 6.18.* (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/display/xe_fb_pin.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "491c499295fb0b90308b230b0a1075dcdf7f4d12",
"status": "affected",
"version": "775d0adc01a55fe0458139330415d86bb3533efe",
"versionType": "git"
},
{
"lessThan": "f03415030579163f791c978741af7f1f2f6510b7",
"status": "affected",
"version": "775d0adc01a55fe0458139330415d86bb3533efe",
"versionType": "git"
},
{
"lessThan": "c457e2c845ccbf2224386029f3da4937ba424db0",
"status": "affected",
"version": "775d0adc01a55fe0458139330415d86bb3533efe",
"versionType": "git"
},
{
"lessThan": "fc648757908304aedbad74f74bf58192aec383db",
"status": "affected",
"version": "775d0adc01a55fe0458139330415d86bb3533efe",
"versionType": "git"
},
{
"status": "affected",
"version": "4854ac2f88e2168ee4da2b152c6711772a8149aa",
"versionType": "git"
},
{
"lessThan": "6.12",
"status": "affected",
"version": "6.11.3",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/xe/display/xe_fb_pin.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.12"
},
{
"lessThan": "6.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.11.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix DPT allocation paths.\n\nRemove the fallback for VRAM to system memory, I tested it and that\ndoesn\u0027t work at all, only a black screen with pipe fault errors were\nobserved.\n\nOn systems with media GT, extra latency is added when accessing stolen\nmemory when the GT is in MC6. Since we additionally aren\u0027t counting how\nmuch memory is used for stolen and we could in theory fill up the\nentire stolen area with DPT\u0027s, avoid using stolen and only use the\ndefault memory region.\n\nUsing stolen may also result in random system hangs under load.\n\n(cherry picked from commit a196406a3831291598fe8e73245914f7acffdfe0)"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:13.979Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/491c499295fb0b90308b230b0a1075dcdf7f4d12"
},
{
"url": "https://git.kernel.org/stable/c/f03415030579163f791c978741af7f1f2f6510b7"
},
{
"url": "https://git.kernel.org/stable/c/c457e2c845ccbf2224386029f3da4937ba424db0"
},
{
"url": "https://git.kernel.org/stable/c/fc648757908304aedbad74f74bf58192aec383db"
}
],
"title": "drm/xe: Fix DPT allocation paths.",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80915",
"datePublished": "2026-09-09T16:13:13.979Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:13.979Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80916 (GCVE-0-2026-80916)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
kcov: fix data corruption and race conditions on PREEMPT_RT
Summary
In the Linux kernel, the following vulnerability has been resolved:
kcov: fix data corruption and race conditions on PREEMPT_RT
syzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the
temporary storage used for saving/restoring remote KCOV state is currently
allocated as the per-CPU area.
On PREEMPT_RT kernels, softirq handlers run as preemptible task threads
(e.g., ksoftirqd). If a softirq context preempts a task running a remote
KCOV session, it safely saves the task's state into the per-CPU area.
However, if that softirq thread is subsequently preempted by a higher-
priority softirq thread on the same CPU, the second softirq will overwrite
the same per-CPU area, permanently destroying the original task's KCOV
state.
Fix this data corruption by moving the temporary storage from the per-CPU
area to the per-thread area. Since each softirq thread now owns its own
task context, nested softirq preemption no longer causes data overwrites.
Note that while the temporary storage is now on a per-thread basis, the
per-CPU kcov_percpu_data.lock must be retained, for we need to ensure that
kcov_remote_start() and kcov_remote_stop() operate atomically without
racing against asynchronous interrupts that manipulate the current task's
KCOV state.
It is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()
has already called panic() before returning NULL, for there will be no
OOM-killable userspace processes when __init function of built-in module
runs. But this patch also fixes crashing the kernel when vmalloc_node()
in kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL
but kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in
(1) doing vmalloc() in kcov_remote_start() despite !in_task() context
(2) out-of-array-bounds access if (1) succeeded but
kcov->remote_size < CONFIG_KCOV_IRQ_AREA_SIZE
(3) always leak memory allocated by (1), eventually killing all
OOM-killable userspace processes
problems.
Severity
No CVSS data available.
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < ef7048d8a614c5f5a9b20513a5428101a744514e
(git)
Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < 8ed3ddf23d39bf5338406bd9f8863d44748cf6ce (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < 5dc59fc959b2b5742985d7ef24bccd1868217dc2 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < a2fb8222cde23b0001812ed3acb7c0ea36dd94e2 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < 18799e858b407bf355383c9dd6c06477aa437134 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < e11f5b48c82703242a3be7a7ae4b4940b4cb4610 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < 22670d1552fe155822b2abf91f920925f7d067b4 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761 (git) Affected: 5ff3b30ab57da82d8db4f14662a2858cabfbc2c0 , < 2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c (git) |
|
| Linux | Linux |
Affected:
5.8
Unaffected: 0 , < 5.8 (semver) Unaffected: 5.10.269 , ≤ 5.10.* (semver) Unaffected: 5.15.220 , ≤ 5.15.* (semver) Unaffected: 6.1.185 , ≤ 6.1.* (semver) Unaffected: 6.6.154 , ≤ 6.6.* (semver) Unaffected: 6.12.106 , ≤ 6.12.* (semver) Unaffected: 6.18.47 , ≤ 6.18.* (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2.1 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/sched.h",
"kernel/kcov.c",
"lib/Kconfig.debug"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "ef7048d8a614c5f5a9b20513a5428101a744514e",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "8ed3ddf23d39bf5338406bd9f8863d44748cf6ce",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "5dc59fc959b2b5742985d7ef24bccd1868217dc2",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "a2fb8222cde23b0001812ed3acb7c0ea36dd94e2",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "18799e858b407bf355383c9dd6c06477aa437134",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "e11f5b48c82703242a3be7a7ae4b4940b4cb4610",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "22670d1552fe155822b2abf91f920925f7d067b4",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
},
{
"lessThan": "2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c",
"status": "affected",
"version": "5ff3b30ab57da82d8db4f14662a2858cabfbc2c0",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/sched.h",
"kernel/kcov.c",
"lib/Kconfig.debug"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.8"
},
{
"lessThan": "5.8",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.8",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.8",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkcov: fix data corruption and race conditions on PREEMPT_RT\n\nsyzbot is reporting KCOV state corruption on PREEMPT_RT kernels, for the\ntemporary storage used for saving/restoring remote KCOV state is currently\nallocated as the per-CPU area.\n\nOn PREEMPT_RT kernels, softirq handlers run as preemptible task threads\n(e.g., ksoftirqd). If a softirq context preempts a task running a remote\nKCOV session, it safely saves the task\u0027s state into the per-CPU area.\nHowever, if that softirq thread is subsequently preempted by a higher-\npriority softirq thread on the same CPU, the second softirq will overwrite\nthe same per-CPU area, permanently destroying the original task\u0027s KCOV\nstate.\n\nFix this data corruption by moving the temporary storage from the per-CPU\narea to the per-thread area. Since each softirq thread now owns its own\ntask context, nested softirq preemption no longer causes data overwrites.\n\nNote that while the temporary storage is now on a per-thread basis, the\nper-CPU kcov_percpu_data.lock must be retained, for we need to ensure that\nkcov_remote_start() and kcov_remote_stop() operate atomically without\nracing against asynchronous interrupts that manipulate the current task\u0027s\nKCOV state.\n\nIt is likely that GFP_KERNEL allocation by vmalloc_node() in kcov_init()\nhas already called panic() before returning NULL, for there will be no\nOOM-killable userspace processes when __init function of built-in module\nruns. But this patch also fixes crashing the kernel when vmalloc_node()\nin kcov_init() returned NULL, for kcov_init() left per-CPU irq_area == NULL\nbut kcov_remote_start() depends on per-CPU irq_area != NULL, resulting in\n\n (1) doing vmalloc() in kcov_remote_start() despite !in_task() context\n\n (2) out-of-array-bounds access if (1) succeeded but\n kcov-\u003eremote_size \u003c CONFIG_KCOV_IRQ_AREA_SIZE\n\n (3) always leak memory allocated by (1), eventually killing all\n OOM-killable userspace processes\n\nproblems."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:14.587Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/ef7048d8a614c5f5a9b20513a5428101a744514e"
},
{
"url": "https://git.kernel.org/stable/c/8ed3ddf23d39bf5338406bd9f8863d44748cf6ce"
},
{
"url": "https://git.kernel.org/stable/c/5dc59fc959b2b5742985d7ef24bccd1868217dc2"
},
{
"url": "https://git.kernel.org/stable/c/a2fb8222cde23b0001812ed3acb7c0ea36dd94e2"
},
{
"url": "https://git.kernel.org/stable/c/18799e858b407bf355383c9dd6c06477aa437134"
},
{
"url": "https://git.kernel.org/stable/c/e11f5b48c82703242a3be7a7ae4b4940b4cb4610"
},
{
"url": "https://git.kernel.org/stable/c/22670d1552fe155822b2abf91f920925f7d067b4"
},
{
"url": "https://git.kernel.org/stable/c/f8c9a3ec36b4ee3d4701b9be08f40e7bfbf89761"
},
{
"url": "https://git.kernel.org/stable/c/2eed77fdcb0cc48e8eccb2bcd4b7f2c6d650e84c"
}
],
"title": "kcov: fix data corruption and race conditions on PREEMPT_RT",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80916",
"datePublished": "2026-09-09T16:13:14.587Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:14.587Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80917 (GCVE-0-2026-80917)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
Summary
In the Linux kernel, the following vulnerability has been resolved:
PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
On 32-bit systems the config space is too large to ioremap in one go, so
pci_ecam_create() maps each bus segment separately and relies on the
->add_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in
cfg->winp[]. pci_ecam_map_bus() then uses that mapping as the base for
every config access.
The generic ECAM ops (pci_generic_ecam_ops) already provide the ->add_bus
and ->remove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c
do not. As a result, on a 32-bit host using "pci-host-cam-generic" the
per-bus mapping is never set up and the first config read dereferences a
NULL base, crashing during bus enumeration:
Unable to handle kernel NULL pointer dereference at virtual address 00000800
Oops [#1]
CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43
Hardware name: Digilent Nexys-Video-A7 RV32 (DT)
epc : pci_generic_config_read+0x40/0xb0
ra : pci_generic_config_read+0x2c/0xb0
[<c038db9c>] pci_generic_config_read+0x40/0xb0
[<c038da04>] pci_bus_read_config_dword+0x50/0xb0
[<c0391e94>] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec
[<c039245c>] pci_scan_single_device+0xa4/0x11c
[<c0392570>] pci_scan_slot+0x9c/0x23c
[<c039388c>] pci_scan_child_bus_extend+0x58/0x2f4
[<c0393db0>] pci_scan_root_bus_bridge+0x64/0xe8
[<c0393e54>] pci_host_probe+0x20/0xc8
[<c03bc6f4>] pci_host_common_probe+0x144/0x1e4
Fix this by giving the CAM ops the same ->add_bus/->remove_bus callbacks.
Since pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,
move the CAM ops definition there as pci_generic_cam_ops (mirroring
pci_generic_ecam_ops) and export it for pci-host-generic.c to reference.
[mani: removed timestamp from log]
Severity
No CVSS data available.
Assigner
References
8 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
8fe55ef23387ce3c7488375b1fd539420d7654bb , < 5e52eb0290f66ba0732956dcb1e365b5ca3c5108
(git)
Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < baf9b0383ff770fdff123d3a832f3a99641d96dd (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < 8d08713ec83a18526d1ed1fd5f0d2b901d103a10 (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < 74456843f18ba7f3045974d7e8b88ab993152b8c (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < 0c55707bd5d0d7670704cfd0dda933809b052f67 (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < a199293f3038db8d31d47aa60f1e18272cd82354 (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < 0916948026f623844acd08888f7cbedbf1c48d6b (git) Affected: 8fe55ef23387ce3c7488375b1fd539420d7654bb , < 008cb88edb41f3c7c8e0ed763ff9f26719830984 (git) Affected: 0b5877a1aeacdbf32b3bea91326592004ec7806f (git) Affected: a037ebbe72a4f98495b193112e2b2000e5e09eb5 (git) Affected: 5.12.19 , < 5.13 (semver) Affected: 5.13.4 , < 5.14 (semver) |
|
| Linux | Linux |
Affected:
5.14
Unaffected: 0 , < 5.14 (semver) Unaffected: 5.15.218 , ≤ 5.15.* (semver) Unaffected: 6.1.185 , ≤ 6.1.* (semver) Unaffected: 6.6.154 , ≤ 6.6.* (semver) Unaffected: 6.12.106 , ≤ 6.12.* (semver) Unaffected: 6.18.47 , ≤ 6.18.* (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2.1 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/pci/controller/pci-host-generic.c",
"drivers/pci/ecam.c",
"include/linux/pci-ecam.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "5e52eb0290f66ba0732956dcb1e365b5ca3c5108",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "baf9b0383ff770fdff123d3a832f3a99641d96dd",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "8d08713ec83a18526d1ed1fd5f0d2b901d103a10",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "74456843f18ba7f3045974d7e8b88ab993152b8c",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "0c55707bd5d0d7670704cfd0dda933809b052f67",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "a199293f3038db8d31d47aa60f1e18272cd82354",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "0916948026f623844acd08888f7cbedbf1c48d6b",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"lessThan": "008cb88edb41f3c7c8e0ed763ff9f26719830984",
"status": "affected",
"version": "8fe55ef23387ce3c7488375b1fd539420d7654bb",
"versionType": "git"
},
{
"status": "affected",
"version": "0b5877a1aeacdbf32b3bea91326592004ec7806f",
"versionType": "git"
},
{
"status": "affected",
"version": "a037ebbe72a4f98495b193112e2b2000e5e09eb5",
"versionType": "git"
},
{
"lessThan": "5.13",
"status": "affected",
"version": "5.12.19",
"versionType": "semver"
},
{
"lessThan": "5.14",
"status": "affected",
"version": "5.13.4",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/pci/controller/pci-host-generic.c",
"drivers/pci/ecam.c",
"include/linux/pci-ecam.h"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.14"
},
{
"lessThan": "5.14",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.14",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.12.19",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.13.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems\n\nOn 32-bit systems the config space is too large to ioremap in one go, so\npci_ecam_create() maps each bus segment separately and relies on the\n-\u003eadd_bus callback (pci_ecam_add_bus) to populate the per-bus mapping in\ncfg-\u003ewinp[]. pci_ecam_map_bus() then uses that mapping as the base for\nevery config access.\n\nThe generic ECAM ops (pci_generic_ecam_ops) already provide the -\u003eadd_bus\nand -\u003eremove_bus callbacks, but the CAM (legacy) ops in pci-host-generic.c\ndo not. As a result, on a 32-bit host using \"pci-host-cam-generic\" the\nper-bus mapping is never set up and the first config read dereferences a\nNULL base, crashing during bus enumeration:\n\n Unable to handle kernel NULL pointer dereference at virtual address 00000800\n Oops [#1]\n CPU: 0 PID: 1 Comm: swapper Not tainted 6.9.7+ #43\n Hardware name: Digilent Nexys-Video-A7 RV32 (DT)\n epc : pci_generic_config_read+0x40/0xb0\n ra : pci_generic_config_read+0x2c/0xb0\n [\u003cc038db9c\u003e] pci_generic_config_read+0x40/0xb0\n [\u003cc038da04\u003e] pci_bus_read_config_dword+0x50/0xb0\n [\u003cc0391e94\u003e] pci_bus_generic_read_dev_vendor_id+0x3c/0x1ec\n [\u003cc039245c\u003e] pci_scan_single_device+0xa4/0x11c\n [\u003cc0392570\u003e] pci_scan_slot+0x9c/0x23c\n [\u003cc039388c\u003e] pci_scan_child_bus_extend+0x58/0x2f4\n [\u003cc0393db0\u003e] pci_scan_root_bus_bridge+0x64/0xe8\n [\u003cc0393e54\u003e] pci_host_probe+0x20/0xc8\n [\u003cc03bc6f4\u003e] pci_host_common_probe+0x144/0x1e4\n\nFix this by giving the CAM ops the same -\u003eadd_bus/-\u003eremove_bus callbacks.\nSince pci_ecam_add_bus() and pci_ecam_remove_bus() are static to ecam.c,\nmove the CAM ops definition there as pci_generic_cam_ops (mirroring\npci_generic_ecam_ops) and export it for pci-host-generic.c to reference.\n\n[mani: removed timestamp from log]"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:15.202Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/5e52eb0290f66ba0732956dcb1e365b5ca3c5108"
},
{
"url": "https://git.kernel.org/stable/c/baf9b0383ff770fdff123d3a832f3a99641d96dd"
},
{
"url": "https://git.kernel.org/stable/c/8d08713ec83a18526d1ed1fd5f0d2b901d103a10"
},
{
"url": "https://git.kernel.org/stable/c/74456843f18ba7f3045974d7e8b88ab993152b8c"
},
{
"url": "https://git.kernel.org/stable/c/0c55707bd5d0d7670704cfd0dda933809b052f67"
},
{
"url": "https://git.kernel.org/stable/c/a199293f3038db8d31d47aa60f1e18272cd82354"
},
{
"url": "https://git.kernel.org/stable/c/0916948026f623844acd08888f7cbedbf1c48d6b"
},
{
"url": "https://git.kernel.org/stable/c/008cb88edb41f3c7c8e0ed763ff9f26719830984"
}
],
"title": "PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80917",
"datePublished": "2026-09-09T16:13:15.202Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:15.202Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80918 (GCVE-0-2026-80918)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
HID: core: fix number/pointer type confusion on long items
Summary
In the Linux kernel, the following vulnerability has been resolved:
HID: core: fix number/pointer type confusion on long items
When fetch_item() is called by hid_scan_report() on an item with
HID_ITEM_TAG_LONG, it stores a pointer to the item data in
item->data.longdata instead of storing a value directly in
item->data.{u8/u16/u32}.
When item_udata() or item_sdata() encounters such an item, it incorrectly
assumes that the item is in short format, and therefore returns the lower
part of a kernel pointer reinterpreted as a number.
When a HID device is connected whose descriptor contains a
HID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this
causes the lower half of a kernel pointer to be printed into dmesg as a
number, like this:
hid (null): invalid report_size 107953555
To fix it, let item_udata() and item_sdata() verify that the item is in
short format.
Note that this bug only affects hid_scan_report(), while the main parsing
pass hid_parse_collections() will always bail out when encountering a long
item.
Sidenote: There are currently no users of data.longdata; maybe we should
just remove any parsing of long-format descriptors as a follow-up.
Severity
No CVSS data available.
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
3dc8fc083dbfeede7b63a0c07581192e97711365 , < bed7fe3a936b6bdd84671385951397ca673cf6e7
(git)
Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < aec2c2ec87d4ec1f098979f68cd81b29f031c8cb (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < 634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996 (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < abec577de5fc16cd5caae42f97cdcd0983c06d66 (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < dd8035dec26e98204d6e4a6e0cee5c4d329b3d7e (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < 1fa1591efd417e39e5e164bebea8ca7a3837c469 (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < e60159f5ea60254a5c3de4ea4f2f939f0171031b (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < e542edada3f79387c0ac2a528cebf01f4ef47df8 (git) Affected: 3dc8fc083dbfeede7b63a0c07581192e97711365 , < 28abce951343fcec26e397610868efa4e1395c3f (git) |
|
| Linux | Linux |
Affected:
3.12
Unaffected: 0 , < 3.12 (semver) Unaffected: 5.10.267 , ≤ 5.10.* (semver) Unaffected: 5.15.218 , ≤ 5.15.* (semver) Unaffected: 6.1.185 , ≤ 6.1.* (semver) Unaffected: 6.6.154 , ≤ 6.6.* (semver) Unaffected: 6.12.106 , ≤ 6.12.* (semver) Unaffected: 6.18.47 , ≤ 6.18.* (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2.1 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "bed7fe3a936b6bdd84671385951397ca673cf6e7",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "aec2c2ec87d4ec1f098979f68cd81b29f031c8cb",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "abec577de5fc16cd5caae42f97cdcd0983c06d66",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "dd8035dec26e98204d6e4a6e0cee5c4d329b3d7e",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "1fa1591efd417e39e5e164bebea8ca7a3837c469",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "e60159f5ea60254a5c3de4ea4f2f939f0171031b",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "e542edada3f79387c0ac2a528cebf01f4ef47df8",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
},
{
"lessThan": "28abce951343fcec26e397610868efa4e1395c3f",
"status": "affected",
"version": "3dc8fc083dbfeede7b63a0c07581192e97711365",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/hid/hid-core.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "3.12"
},
{
"lessThan": "3.12",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.267",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.218",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.185",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.154",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.106",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.47",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.267",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.218",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.185",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.154",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.106",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.47",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "3.12",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "3.12",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nHID: core: fix number/pointer type confusion on long items\n\nWhen fetch_item() is called by hid_scan_report() on an item with\nHID_ITEM_TAG_LONG, it stores a pointer to the item data in\nitem-\u003edata.longdata instead of storing a value directly in\nitem-\u003edata.{u8/u16/u32}.\n\nWhen item_udata() or item_sdata() encounters such an item, it incorrectly\nassumes that the item is in short format, and therefore returns the lower\npart of a kernel pointer reinterpreted as a number.\n\nWhen a HID device is connected whose descriptor contains a\nHID_GLOBAL_ITEM_TAG_REPORT_SIZE encoded in long format with size=4, this\ncauses the lower half of a kernel pointer to be printed into dmesg as a\nnumber, like this:\n\n hid (null): invalid report_size 107953555\n\nTo fix it, let item_udata() and item_sdata() verify that the item is in\nshort format.\n\nNote that this bug only affects hid_scan_report(), while the main parsing\npass hid_parse_collections() will always bail out when encountering a long\nitem.\n\nSidenote: There are currently no users of data.longdata; maybe we should\njust remove any parsing of long-format descriptors as a follow-up."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:15.799Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/bed7fe3a936b6bdd84671385951397ca673cf6e7"
},
{
"url": "https://git.kernel.org/stable/c/aec2c2ec87d4ec1f098979f68cd81b29f031c8cb"
},
{
"url": "https://git.kernel.org/stable/c/634f498ea5d5e8e01f8d9414d4f45eeaf9ee1996"
},
{
"url": "https://git.kernel.org/stable/c/abec577de5fc16cd5caae42f97cdcd0983c06d66"
},
{
"url": "https://git.kernel.org/stable/c/dd8035dec26e98204d6e4a6e0cee5c4d329b3d7e"
},
{
"url": "https://git.kernel.org/stable/c/1fa1591efd417e39e5e164bebea8ca7a3837c469"
},
{
"url": "https://git.kernel.org/stable/c/e60159f5ea60254a5c3de4ea4f2f939f0171031b"
},
{
"url": "https://git.kernel.org/stable/c/e542edada3f79387c0ac2a528cebf01f4ef47df8"
},
{
"url": "https://git.kernel.org/stable/c/28abce951343fcec26e397610868efa4e1395c3f"
}
],
"title": "HID: core: fix number/pointer type confusion on long items",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80918",
"datePublished": "2026-09-09T16:13:15.799Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:15.799Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80919 (GCVE-0-2026-80919)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
Summary
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
When dumping IB contents from a hung job, amdgpu_devcoredump_format()
acquired the VM root PD's reservation via amdgpu_vm_lock_by_pasid() and
then, for each IB, called amdgpu_bo_reserve() on the BO backing the IB.
Both reservations are reservation_ww_class_mutex objects and neither
used a ww_acquire_ctx, which trips lockdep:
WARNING: possible recursive locking detected
--------------------------------------------
kworker/u128:0 is trying to acquire lock:
ffff88838b16e1f0 (reservation_ww_class_mutex){+.+.}-{4:4},
at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]
but task is already holding lock:
ffff8882f82681f0 (reservation_ww_class_mutex){+.+.}-{4:4},
at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]
Possible unsafe locking scenario:
CPU0
----
lock(reservation_ww_class_mutex);
lock(reservation_ww_class_mutex);
*** DEADLOCK ***
May be due to missing lock nesting notation
Workqueue: events_unbound amdgpu_devcoredump_deferred_work [amdgpu]
Call Trace:
__ww_mutex_lock.constprop.0
ww_mutex_lock
amdgpu_bo_reserve
amdgpu_devcoredump_format+0x1594 [amdgpu]
amdgpu_devcoredump_deferred_work+0xea [amdgpu]
The two reservations are on different BOs in the captured trace, so the
splat is a lockdep-correctness warning, not an observed deadlock. It
becomes a real self-deadlock whenever the IB BO shares its dma_resv with
the root PD (the always-valid case, see amdgpu_vm_is_bo_always_valid()):
amdgpu_bo_reserve(abo) re-acquires the same ww_mutex without a ticket
and blocks forever. With amdgpu.gpu_recovery=0 the timeout handler
refires every ~2 s and each invocation produces this splat, drowning the
kernel ring buffer.
Now that amdgpu_vm_lock_by_pasid() takes a drm_exec context, move the IB
dumping into a separate helper that locks the root PD and every IB BO
together in a single drm_exec ticket. DRM_EXEC_IGNORE_DUPLICATES handles
IB BOs that share a dma_resv (e.g. always-valid BOs, or two IBs backed
by the same BO). Every lock is now a top-level acquire under one
ww_acquire_ctx, so the recursive ww_mutex condition is gone, and the
per-IB amdgpu_bo_reserve()/amdgpu_bo_unref() dance -- including a BO
refcount leak on the amdgpu_bo_reserve() failure path -- is removed.
(cherry picked from commit d6bf4242731219ee08ce54c365631e395486651e)
Severity
No CVSS data available.
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
7b15fc2d1f1a00fb99f0146e404ff2600999ec74 , < 4e9b4dee0777ec9c835a4746e2d30382dd9d1044
(git)
Affected: 7b15fc2d1f1a00fb99f0146e404ff2600999ec74 , < 7152b248dc3c8d5fa8629e99ed5655dd41b51562 (git) |
|
| Linux | Linux |
Affected:
7.1
Unaffected: 0 , < 7.1 (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "4e9b4dee0777ec9c835a4746e2d30382dd9d1044",
"status": "affected",
"version": "7b15fc2d1f1a00fb99f0146e404ff2600999ec74",
"versionType": "git"
},
{
"lessThan": "7152b248dc3c8d5fa8629e99ed5655dd41b51562",
"status": "affected",
"version": "7b15fc2d1f1a00fb99f0146e404ff2600999ec74",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/gpu/drm/amd/amdgpu/amdgpu_dev_coredump.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "7.1"
},
{
"lessThan": "7.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "7.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "7.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format\n\nWhen dumping IB contents from a hung job, amdgpu_devcoredump_format()\nacquired the VM root PD\u0027s reservation via amdgpu_vm_lock_by_pasid() and\nthen, for each IB, called amdgpu_bo_reserve() on the BO backing the IB.\nBoth reservations are reservation_ww_class_mutex objects and neither\nused a ww_acquire_ctx, which trips lockdep:\n\n WARNING: possible recursive locking detected\n --------------------------------------------\n kworker/u128:0 is trying to acquire lock:\n ffff88838b16e1f0 (reservation_ww_class_mutex){+.+.}-{4:4},\n at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]\n\n but task is already holding lock:\n ffff8882f82681f0 (reservation_ww_class_mutex){+.+.}-{4:4},\n at: amdgpu_devcoredump_format+0x1594/0x23f0 [amdgpu]\n\n Possible unsafe locking scenario:\n CPU0\n ----\n lock(reservation_ww_class_mutex);\n lock(reservation_ww_class_mutex);\n\n *** DEADLOCK ***\n May be due to missing lock nesting notation\n\n Workqueue: events_unbound amdgpu_devcoredump_deferred_work [amdgpu]\n Call Trace:\n __ww_mutex_lock.constprop.0\n ww_mutex_lock\n amdgpu_bo_reserve\n amdgpu_devcoredump_format+0x1594 [amdgpu]\n amdgpu_devcoredump_deferred_work+0xea [amdgpu]\n\nThe two reservations are on different BOs in the captured trace, so the\nsplat is a lockdep-correctness warning, not an observed deadlock. It\nbecomes a real self-deadlock whenever the IB BO shares its dma_resv with\nthe root PD (the always-valid case, see amdgpu_vm_is_bo_always_valid()):\namdgpu_bo_reserve(abo) re-acquires the same ww_mutex without a ticket\nand blocks forever. With amdgpu.gpu_recovery=0 the timeout handler\nrefires every ~2 s and each invocation produces this splat, drowning the\nkernel ring buffer.\n\nNow that amdgpu_vm_lock_by_pasid() takes a drm_exec context, move the IB\ndumping into a separate helper that locks the root PD and every IB BO\ntogether in a single drm_exec ticket. DRM_EXEC_IGNORE_DUPLICATES handles\nIB BOs that share a dma_resv (e.g. always-valid BOs, or two IBs backed\nby the same BO). Every lock is now a top-level acquire under one\nww_acquire_ctx, so the recursive ww_mutex condition is gone, and the\nper-IB amdgpu_bo_reserve()/amdgpu_bo_unref() dance -- including a BO\nrefcount leak on the amdgpu_bo_reserve() failure path -- is removed.\n\n(cherry picked from commit d6bf4242731219ee08ce54c365631e395486651e)"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:16.415Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/4e9b4dee0777ec9c835a4746e2d30382dd9d1044"
},
{
"url": "https://git.kernel.org/stable/c/7152b248dc3c8d5fa8629e99ed5655dd41b51562"
}
],
"title": "drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80919",
"datePublished": "2026-09-09T16:13:16.415Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:16.415Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80920 (GCVE-0-2026-80920)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:13 – Updated: 2026-09-09 16:13
VLAI
EPSS
VEX
Title
io_uring: defer eventfd signaling when queued from a wakeup handler
Summary
In the Linux kernel, the following vulnerability has been resolved:
io_uring: defer eventfd signaling when queued from a wakeup handler
io_req_local_work_add() signals the CQ ring eventfd inline when it is the
one to push the first entry onto ->work_list. For DEFER_TASKRUN rings that
add is frequently done from a waitqueue wakeup handler, where an
arbitrary waitqueue lock is held.
eventfd_signal_mask() only refuses to recurse when current->in_eventfd
is set, but that bit is set by eventfd_signal_mask() itself. If the wake
chain starts somewhere else, signal goes out inline and can feed back
into epoll.
Add IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three
waitqueue callbacks, and use it to force io_eventfd_signal() down the
existing call_rcu_hurry() deferral instead of signaling inline.
Severity
No CVSS data available.
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
21a091b970cdbcf3e8ff829234b51be6f9192766 , < e22f4494cc9487d326e5e3067f33dea7c1e442b2
(git)
Affected: 21a091b970cdbcf3e8ff829234b51be6f9192766 , < b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f (git) Affected: 21a091b970cdbcf3e8ff829234b51be6f9192766 , < 40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a (git) Affected: 21a091b970cdbcf3e8ff829234b51be6f9192766 , < cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e (git) |
|
| Linux | Linux |
Affected:
6.1
Unaffected: 0 , < 6.1 (semver) Unaffected: 6.18.49 , ≤ 6.18.* (semver) Unaffected: 7.1.11 , ≤ 7.1.* (semver) Unaffected: 7.2.1 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"include/linux/io_uring_types.h",
"io_uring/eventfd.c",
"io_uring/eventfd.h",
"io_uring/futex.c",
"io_uring/io_uring.c",
"io_uring/poll.c",
"io_uring/tw.c",
"io_uring/waitid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "e22f4494cc9487d326e5e3067f33dea7c1e442b2",
"status": "affected",
"version": "21a091b970cdbcf3e8ff829234b51be6f9192766",
"versionType": "git"
},
{
"lessThan": "b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f",
"status": "affected",
"version": "21a091b970cdbcf3e8ff829234b51be6f9192766",
"versionType": "git"
},
{
"lessThan": "40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a",
"status": "affected",
"version": "21a091b970cdbcf3e8ff829234b51be6f9192766",
"versionType": "git"
},
{
"lessThan": "cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e",
"status": "affected",
"version": "21a091b970cdbcf3e8ff829234b51be6f9192766",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"include/linux/io_uring_types.h",
"io_uring/eventfd.c",
"io_uring/eventfd.h",
"io_uring/futex.c",
"io_uring/io_uring.c",
"io_uring/poll.c",
"io_uring/tw.c",
"io_uring/waitid.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.1"
},
{
"lessThan": "6.1",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.11",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.1",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.11",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.1",
"versionStartIncluding": "6.1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: defer eventfd signaling when queued from a wakeup handler\n\nio_req_local_work_add() signals the CQ ring eventfd inline when it is the\none to push the first entry onto -\u003ework_list. For DEFER_TASKRUN rings that\nadd is frequently done from a waitqueue wakeup handler, where an\narbitrary waitqueue lock is held.\n\neventfd_signal_mask() only refuses to recurse when current-\u003ein_eventfd\nis set, but that bit is set by eventfd_signal_mask() itself. If the wake\nchain starts somewhere else, signal goes out inline and can feed back\ninto epoll.\n\nAdd IOU_F_TWQ_IN_WAKE, set it on the task_work add done from the three\nwaitqueue callbacks, and use it to force io_eventfd_signal() down the\nexisting call_rcu_hurry() deferral instead of signaling inline."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:13:17.023Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/e22f4494cc9487d326e5e3067f33dea7c1e442b2"
},
{
"url": "https://git.kernel.org/stable/c/b6bb334b0e9348887e3e55e1f494b0c3b8fbf59f"
},
{
"url": "https://git.kernel.org/stable/c/40b6ccf68731809ceb85c6e9f0f8f2ed61c7aa5a"
},
{
"url": "https://git.kernel.org/stable/c/cd305ee3633a45fcf5f3a5d83f99f3cb77d87b6e"
}
],
"title": "io_uring: defer eventfd signaling when queued from a wakeup handler",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80920",
"datePublished": "2026-09-09T16:13:17.023Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:13:17.023Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80921 (GCVE-0-2026-80921)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:19 – Updated: 2026-09-10 05:50
VLAI
EPSS
VEX
Title
KVM: s390: vsie: zero stale crypto bits
Summary
In the Linux kernel, the following vulnerability has been resolved:
KVM: s390: vsie: zero stale crypto bits
When shadowing crypto access bits from a format0 apcb (crycb 0 or 1),
the bits 64..255 are unchanged from whatever is in the vsie page in the
crycb and thus in the apcb. This gives a nested guest potential access
to a device no longer available. Zero out the remaining bits.
Severity
8.8 (High)
Assigner
References
9 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < d110b3297f11ef227098b8a82ade2d5f123b7d2f
(git)
Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 59d51550b5cb916bda037673a721a404b3b47a0d (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < f6079dca67eccb5eabef9f72437948c66dc5131f (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 087c19cc60a8caa1a08e1e434c8be2caf6c27733 (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 7d23489f51109e3ebba5b5db8c5f0185af7b7fdf (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 935eeba276012916c76243e5cbb843efd8fdb75d (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < d4bcd2df6d0d2af916b4fe1a533958778ea7c45b (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6 (git) Affected: 6b79de4b056e5a2febc0c61233d8f0ad7868e49c , < 34d5b5b646c91cfb9338d7a12c955a70ffb8c66b (git) |
|
| Linux | Linux |
Affected:
4.20
Unaffected: 0 , < 4.20 (semver) Unaffected: 5.10.269 , ≤ 5.10.* (semver) Unaffected: 5.15.220 , ≤ 5.15.* (semver) Unaffected: 6.1.187 , ≤ 6.1.* (semver) Unaffected: 6.6.156 , ≤ 6.6.* (semver) Unaffected: 6.12.108 , ≤ 6.12.* (semver) Unaffected: 6.18.49 , ≤ 6.18.* (semver) Unaffected: 7.1.13 , ≤ 7.1.* (semver) Unaffected: 7.2.3 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/vsie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "d110b3297f11ef227098b8a82ade2d5f123b7d2f",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "59d51550b5cb916bda037673a721a404b3b47a0d",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "f6079dca67eccb5eabef9f72437948c66dc5131f",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "087c19cc60a8caa1a08e1e434c8be2caf6c27733",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "7d23489f51109e3ebba5b5db8c5f0185af7b7fdf",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "935eeba276012916c76243e5cbb843efd8fdb75d",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "d4bcd2df6d0d2af916b4fe1a533958778ea7c45b",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
},
{
"lessThan": "34d5b5b646c91cfb9338d7a12c955a70ffb8c66b",
"status": "affected",
"version": "6b79de4b056e5a2febc0c61233d8f0ad7868e49c",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"arch/s390/kvm/vsie.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "4.20"
},
{
"lessThan": "4.20",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.269",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.269",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "4.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "4.20",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: s390: vsie: zero stale crypto bits\n\nWhen shadowing crypto access bits from a format0 apcb (crycb 0 or 1),\nthe bits 64..255 are unchanged from whatever is in the vsie page in the\ncrycb and thus in the apcb. This gives a nested guest potential access\nto a device no longer available. Zero out the remaining bits."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 8.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - The bug is reached when an s390 KVM guest executes the privileged SIE instruction (B2/14), intercepted through handle_instruction() to kvm_s390_handle_vsie() and setup_apcb10(); that is a local guest/KVM ioctl path with no network, Bluetooth, or USB exposure.\nAC:L - An L1 guest that first runs a FORMAT-2 nested SCB (setup_apcb11 fills all 256 APCB bits) and then a FORMAT-0/1 SCB on a recycled vsie page hits setup_apcb10() deterministically; get_vsie_page() reuses pages without clearing crycb, so leftover bits 64-255 persist with no race or uncontrolled memory layout.\nPR:L - SIE requires guest supervisor state, i.e. the tenant guest kernel or an unprivileged host kvm-group user running QEMU, not host root; kvm_s390_handle_vsie() has no host capability gate, and user namespaces cannot substitute for this path, so privileges stay Low rather than High.\nUI:N - The attacker guest issues SIE and uses the over-permissive shadow APCB itself; vsie page reuse and crycb shadowing run automatically inside KVM with no victim mount, click, or other user action.\nS:C - Leftover APCB bits grant a nested guest millicode-enforced access to host AP adapters/domains outside its delegated matrix, crossing the KVM nested-virt and vfio-ap passthrough boundary into another guest\u0027s or the host zcrypt authority, equivalent to an IOMMU/device isolation bypass.\nC:H - Unauthorized APQNs let the nested guest issue NQAP/DQAP against queues that may now belong to the host zcrypt stack or another tenant, disclosing cryptographic request/response data and key material on those adapters/domains.\nI:H - The nested guest can enqueue arbitrary AP requests and change hardware queue state on adapters and domains 64-255 that the current shadow should have cleared, corrupting crypto operations the host believes are exclusive to another consumer.\nA:H - With those leftover APQNs the nested guest can PQAP(ZAPQ)-reset or flood shared queues, denying host or sibling-guest crypto services (pkey, secure-key LUKS, openCryptoki) that depend on the same physical adapter/domain."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-10T05:50:22.520Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/d110b3297f11ef227098b8a82ade2d5f123b7d2f"
},
{
"url": "https://git.kernel.org/stable/c/59d51550b5cb916bda037673a721a404b3b47a0d"
},
{
"url": "https://git.kernel.org/stable/c/f6079dca67eccb5eabef9f72437948c66dc5131f"
},
{
"url": "https://git.kernel.org/stable/c/087c19cc60a8caa1a08e1e434c8be2caf6c27733"
},
{
"url": "https://git.kernel.org/stable/c/7d23489f51109e3ebba5b5db8c5f0185af7b7fdf"
},
{
"url": "https://git.kernel.org/stable/c/935eeba276012916c76243e5cbb843efd8fdb75d"
},
{
"url": "https://git.kernel.org/stable/c/d4bcd2df6d0d2af916b4fe1a533958778ea7c45b"
},
{
"url": "https://git.kernel.org/stable/c/29b4f7bc2991313bd3e6f6fb8fdf1b173f086dd6"
},
{
"url": "https://git.kernel.org/stable/c/34d5b5b646c91cfb9338d7a12c955a70ffb8c66b"
}
],
"title": "KVM: s390: vsie: zero stale crypto bits",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80921",
"datePublished": "2026-09-09T16:19:42.335Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-10T05:50:22.520Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80922 (GCVE-0-2026-80922)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:19 – Updated: 2026-09-09 16:19
VLAI
EPSS
VEX
Title
crypto: qcom-rng - Allow zero as a random number
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: qcom-rng - Allow zero as a random number
Zero is a valid random number and needs to be allowed. Otherwise the
output is distinguishable from random.
Severity
No CVSS data available.
Assigner
References
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
f29cd5bb64c258f29b4c49452532481f50eb43ca , < 813e6718a199befc4f26f54bdd899fbfa11515e5
(git)
Affected: f29cd5bb64c258f29b4c49452532481f50eb43ca , < 4c0018320942003bfedd0a1c4cce3f036d363a7f (git) Affected: f29cd5bb64c258f29b4c49452532481f50eb43ca , < 143c74034a1c47b0a1a64e7ca7153e7739bd1244 (git) Affected: f29cd5bb64c258f29b4c49452532481f50eb43ca , < 3c7101cfc52e378bcb0a46962145e39c9051dd5d (git) Affected: f29cd5bb64c258f29b4c49452532481f50eb43ca , < 4ef04bdc0c9f98836d1638be516f6bf1bad55f69 (git) |
|
| Linux | Linux |
Affected:
6.7
Unaffected: 0 , < 6.7 (semver) Unaffected: 6.12.108 , ≤ 6.12.* (semver) Unaffected: 6.18.49 , ≤ 6.18.* (semver) Unaffected: 7.1.13 , ≤ 7.1.* (semver) Unaffected: 7.2.3 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qcom-rng.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "813e6718a199befc4f26f54bdd899fbfa11515e5",
"status": "affected",
"version": "f29cd5bb64c258f29b4c49452532481f50eb43ca",
"versionType": "git"
},
{
"lessThan": "4c0018320942003bfedd0a1c4cce3f036d363a7f",
"status": "affected",
"version": "f29cd5bb64c258f29b4c49452532481f50eb43ca",
"versionType": "git"
},
{
"lessThan": "143c74034a1c47b0a1a64e7ca7153e7739bd1244",
"status": "affected",
"version": "f29cd5bb64c258f29b4c49452532481f50eb43ca",
"versionType": "git"
},
{
"lessThan": "3c7101cfc52e378bcb0a46962145e39c9051dd5d",
"status": "affected",
"version": "f29cd5bb64c258f29b4c49452532481f50eb43ca",
"versionType": "git"
},
{
"lessThan": "4ef04bdc0c9f98836d1638be516f6bf1bad55f69",
"status": "affected",
"version": "f29cd5bb64c258f29b4c49452532481f50eb43ca",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/crypto/qcom-rng.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.7"
},
{
"lessThan": "6.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "6.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qcom-rng - Allow zero as a random number\n\nZero is a valid random number and needs to be allowed. Otherwise the\noutput is distinguishable from random."
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:19:42.937Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/813e6718a199befc4f26f54bdd899fbfa11515e5"
},
{
"url": "https://git.kernel.org/stable/c/4c0018320942003bfedd0a1c4cce3f036d363a7f"
},
{
"url": "https://git.kernel.org/stable/c/143c74034a1c47b0a1a64e7ca7153e7739bd1244"
},
{
"url": "https://git.kernel.org/stable/c/3c7101cfc52e378bcb0a46962145e39c9051dd5d"
},
{
"url": "https://git.kernel.org/stable/c/4ef04bdc0c9f98836d1638be516f6bf1bad55f69"
}
],
"title": "crypto: qcom-rng - Allow zero as a random number",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80922",
"datePublished": "2026-09-09T16:19:42.937Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:19:42.937Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-80923 (GCVE-0-2026-80923)
Vulnerability from cvelistv5 – Published: 2026-09-09 16:19 – Updated: 2026-09-09 16:19
VLAI
EPSS
VEX
Title
xhci: dbgtty: Fix unregister on tty_register_driver() failure
Summary
In the Linux kernel, the following vulnerability has been resolved:
xhci: dbgtty: Fix unregister on tty_register_driver() failure
If tty_register_driver() fails, it drops the reference, but fails to set
the global dbc_tty_driver to NULL, causing the unregister to be called
again when module exits.
On module unload dbc_tty_exit() only gates its cleanup on the driver
pointer being non-NULL, so it operates on the already-freed driver:
module_init(xhci_hcd_init)
xhci_hcd_init()
xhci_dbc_init() [return value ignored]
dbc_tty_init()
tty_register_driver() fails
tty_driver_kref_put() -> driver freed
(dbc_tty_driver left dangling)
...
module_exit(xhci_hcd_fini)
xhci_hcd_fini()
xhci_dbc_exit()
dbc_tty_exit()
if (dbc_tty_driver) -> true (dangling)
tty_unregister_driver() -> use-after-free
Severity
No CVSS data available.
Assigner
References
8 references
Impacted products
2 products
| Vendor | Product | Version | |
|---|---|---|---|
| Linux | Linux |
Affected:
4521f16139409cdf9462c7325d43454462cff6c3 , < 01b7bc0938061f2fd46e0094f6483d8c6c02f7d3
(git)
Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < 43635ff6401ca0e0ed21875379eeded921321525 (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < eaca2814f32b9872a332326324b9e83e01f156d2 (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < 943f976c93e70563b132f5585ff68b08c89641a2 (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < 0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922 (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < 33ed35ca629477f57e0dd1d77d6df96cf5a9eb55 (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < 0e469b94fbba8eb03666da41dd1082b793c50c1a (git) Affected: 4521f16139409cdf9462c7325d43454462cff6c3 , < a916fa66a43e10f63198b6ce978badffc678821a (git) |
|
| Linux | Linux |
Affected:
5.9
Unaffected: 0 , < 5.9 (semver) Unaffected: 5.15.220 , ≤ 5.15.* (semver) Unaffected: 6.1.187 , ≤ 6.1.* (semver) Unaffected: 6.6.156 , ≤ 6.6.* (semver) Unaffected: 6.12.108 , ≤ 6.12.* (semver) Unaffected: 6.18.49 , ≤ 6.18.* (semver) Unaffected: 7.1.13 , ≤ 7.1.* (semver) Unaffected: 7.2.3 , ≤ 7.2.* (semver) Unaffected: 7.3-rc1 , ≤ * (original_commit_for_fix) |
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"drivers/usb/host/xhci-dbgtty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "01b7bc0938061f2fd46e0094f6483d8c6c02f7d3",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "43635ff6401ca0e0ed21875379eeded921321525",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "eaca2814f32b9872a332326324b9e83e01f156d2",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "943f976c93e70563b132f5585ff68b08c89641a2",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "33ed35ca629477f57e0dd1d77d6df96cf5a9eb55",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "0e469b94fbba8eb03666da41dd1082b793c50c1a",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
},
{
"lessThan": "a916fa66a43e10f63198b6ce978badffc678821a",
"status": "affected",
"version": "4521f16139409cdf9462c7325d43454462cff6c3",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"drivers/usb/host/xhci-dbgtty.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.9"
},
{
"lessThan": "5.9",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.220",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.187",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.156",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.108",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.2.*",
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.220",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.187",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.156",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.108",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.49",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.13",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2.3",
"versionStartIncluding": "5.9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.3-rc1",
"versionStartIncluding": "5.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxhci: dbgtty: Fix unregister on tty_register_driver() failure\n\nIf tty_register_driver() fails, it drops the reference, but fails to set\nthe global dbc_tty_driver to NULL, causing the unregister to be called\nagain when module exits.\n\nOn module unload dbc_tty_exit() only gates its cleanup on the driver\npointer being non-NULL, so it operates on the already-freed driver:\n\n module_init(xhci_hcd_init)\n xhci_hcd_init()\n xhci_dbc_init() [return value ignored]\n dbc_tty_init()\n tty_register_driver() fails\n tty_driver_kref_put() -\u003e driver freed\n (dbc_tty_driver left dangling)\n ...\n module_exit(xhci_hcd_fini)\n xhci_hcd_fini()\n xhci_dbc_exit()\n dbc_tty_exit()\n if (dbc_tty_driver) -\u003e true (dangling)\n tty_unregister_driver() -\u003e use-after-free"
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T16:19:43.538Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/01b7bc0938061f2fd46e0094f6483d8c6c02f7d3"
},
{
"url": "https://git.kernel.org/stable/c/43635ff6401ca0e0ed21875379eeded921321525"
},
{
"url": "https://git.kernel.org/stable/c/eaca2814f32b9872a332326324b9e83e01f156d2"
},
{
"url": "https://git.kernel.org/stable/c/943f976c93e70563b132f5585ff68b08c89641a2"
},
{
"url": "https://git.kernel.org/stable/c/0d0faf3cc44c4d86fc6faf5cea972c0fbe00b922"
},
{
"url": "https://git.kernel.org/stable/c/33ed35ca629477f57e0dd1d77d6df96cf5a9eb55"
},
{
"url": "https://git.kernel.org/stable/c/0e469b94fbba8eb03666da41dd1082b793c50c1a"
},
{
"url": "https://git.kernel.org/stable/c/a916fa66a43e10f63198b6ce978badffc678821a"
}
],
"title": "xhci: dbgtty: Fix unregister on tty_register_driver() failure",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80923",
"datePublished": "2026-09-09T16:19:43.538Z",
"dateReserved": "2026-08-26T14:34:25.801Z",
"dateUpdated": "2026-09-09T16:19:43.538Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Trend slope:
-
(linear fit over daily sighting counts)
Show additional events:
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…
Loading…