← All Advisories

CVE-2026-80851

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-80851

Key Details

CVECVE-2026-80851
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

gtp: serialize PDP context updates

PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP

network device is being unregistered. The latter is serialized by RTNL,

but the generic-netlink delete path only holds RCU.

Running both paths concurrently can therefore make both paths delete the

same PDP context. The issue was found through static analysis and

reproduced on a KASAN-enabled kernel by a simple two-thread program

racing GTP_CMD_DELPDP against RTM_DELLINK:

Oops: general protection fault, probably for non-canonical address

KASAN: maybe wild-memory-access in range

[0xdead000000000120-0xdead000000000127]

RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]

RBP: dead000000000122

The second deletion dereferenced the poisoned hlist pprev pointer.

Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a

shared mutex. Keep the mutex held until the final use of a PDP context in

the NEWPDP path, and keep the RCU read-side section around the complete

PDP context use in the DELPDP path. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-80851
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-80851