« Volver al listado

CVE-2026-80866

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tipc: avoid busy looping in tipc_exit_net()

Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete:

This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups.

Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero.

Leer descripción completaMostrar menos

Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero.

This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.

Detalles técnicos trazas, registros y código del informe original
       while (atomic_read(&tn->wq_count))
               cond_resched();

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80866",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
              "lessThan": "522d1d950b9e3b68190a6de7534827c8dccedb73",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "04c26faa51d1e2fe71cf13c45791f5174c37f986",
              "lessThan": "c1481c94e74c955e0448ddf46b8615a44d840c1e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5195ec5e365a2a9331bfeb585b613a6e94f98dba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.124",
              "lessThan": "5.5",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.42",
              "lessThan": "5.11",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.12.9",
              "lessThan": "5.13",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/tipc/core.c",
            "net/tipc/udp_media.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.13",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/tipc/core.c",
            "net/tipc/udp_media.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T17:16:58.390",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/522d1d950b9e3b68190a6de7534827c8dccedb73",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c1481c94e74c955e0448ddf46b8615a44d840c1e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntipc: avoid busy looping in tipc_exit_net()\n\nBlamed commit introduced a busy-wait loop in tipc_exit_net()\nto wait for pending UDP bearer cleanup works to complete:\n\n       while (atomic_read(&tn->wq_count))\n               cond_resched();\n\nThis loop can busy-wait for a long time if cond_resched() is a NOP. This\ntypically happens if the netns exit is executed by a high priority task,\nor under kernels configured without preemption (CONFIG_PREEMPT_NONE). In\nsuch cases, it wastes CPU cycles and can lead to soft lockups.\n\nFix this by replacing the busy loop with wait_var_event(), allowing the\nthread to sleep properly until the work queue count reaches zero.\n\nAccordingly, update cleanup_bearer() to use atomic_dec_and_test() and\nwake_up_var() to wake up the waiter when the count drops to zero.\n\nThis uses the global wait queue hash table, avoiding the need to bloat\nstruct tipc_net with a wait_queue_head_t. The atomic_dec_and_test()\nprovides the necessary memory barrier to ensure the wakeup is not missed."
    }
  ],
  "lastModified": "2026-09-04T17:16:58.390",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}