CVE-2026-80990
In the Linux kernel, the following vulnerability has been resolved:
net: thunderbolt: Release the Rx HopID that was handed out on mismatch
tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id as a failure and returns without releasing what it got, so that allocation stays live for the rest of the XDomain connection with nothing left holding a reference to it.
Release the id when it is not the one we asked for, the same way the error unwind at the end of the function releases the expected one.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1
- https://git.kernel.org/stable/c/2f1463554d0561a2fead81e3888604e5c1125e29
- https://git.kernel.org/stable/c/47981eb66461ba4e74bbaea0f139adaaeb3991e9
- https://git.kernel.org/stable/c/61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea
- https://git.kernel.org/stable/c/9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80990",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "180b0689425c6fb2b35e69a3316ee38371a782df",
"lessThan": "47981eb66461ba4e74bbaea0f139adaaeb3991e9",
"versionType": "git"
},
{
"status": "affected",
"version": "180b0689425c6fb2b35e69a3316ee38371a782df",
"lessThan": "9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0",
"versionType": "git"
},
{
"status": "affected",
"version": "180b0689425c6fb2b35e69a3316ee38371a782df",
"lessThan": "61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea",
"versionType": "git"
},
{
"status": "affected",
"version": "180b0689425c6fb2b35e69a3316ee38371a782df",
"lessThan": "1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1",
"versionType": "git"
},
{
"status": "affected",
"version": "180b0689425c6fb2b35e69a3316ee38371a782df",
"lessThan": "2f1463554d0561a2fead81e3888604e5c1125e29",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.109",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.50",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.4",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/thunderbolt/main.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-11T20:19:05.867",
"references": [
{
"url": "https://git.kernel.org/stable/c/1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2f1463554d0561a2fead81e3888604e5c1125e29",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/47981eb66461ba4e74bbaea0f139adaaeb3991e9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Release the Rx HopID that was handed out on mismatch\n\ntb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range()\nas the lower bound, so a taken id is not an error there: the allocator\nreturns the next free one above it. tbnet_connected_work() asks for the\npeer's transmit path, treats any other id as a failure and returns\nwithout releasing what it got, so that allocation stays live for the rest\nof the XDomain connection with nothing left holding a reference to it.\n\nRelease the id when it is not the one we asked for, the same way the\nerror unwind at the end of the function releases the expected one."
}
],
"lastModified": "2026-09-14T13:18:53.787",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}