← All Advisories

CVE-2026-80841

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-80841

Key Details

CVECVE-2026-80841
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

net/packet: defer vmalloc TX_RING free until skbs finish

AF_PACKET TX_RING skbs keep a raw pointer to their ring frame. The skb

page references preserve page-backed ring blocks after pg_vec is freed,

but they do not preserve a vmalloc mapping.

tpacket_destruct_skb() currently drops the pending reference before

writing the timestamp and TP_STATUS_AVAILABLE to the frame. Move the

decrement after those stores. The smp_wmb() in __packet_set_status()

orders the frame stores before the decrement.

Also recheck pending TX frames under pg_vec_lock before non-closing

ring replacement, so a racing send cannot add a pending skb between

the initial check and the ring swap.

Ring allocation can produce a mixture of page-backed and vmalloc-backed

blocks. Allocate deferred-work storage during TX ring setup when the

first vmalloc-backed block is encountered, and keep its pointer in the

pg_vec allocation header. If allocation fails, return -ENOMEM from ring

setup. On socket close, a non-NULL pointer identifies a vmalloc-backed

vector without a scan. If TX skbs remain, defer the whole vector to

system_long_wq.

After pg_vec is detached, a late destructor can skip the pending

decrement. Use socket write-memory accounting as the deferred lifetime

gate instead: an skb remains charged through its final sock_wfree(),

after all ring-frame accesses. The delayed work retains a socket

reference and reschedules itself until no TX skbs remain.

Move pending_refcnt release to packet_sock_destruct() so late skb

destructors and deferred cleanup can safely use it after

packet_release(). Page-backed teardown remains synchronous, and no lock

is added to the TX completion hot path. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-80841
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-80841