VDB

CVE-2026-80987

CVE-2026-80987 PUBLISHED CVSS 7.5 HIGH

Reported by Linux · Published September 11, 2026

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enqueue() before acquiring a queue entry and return -EMSGSIZE. The caller retains ownership of the buffer, and the preceding netdev patch frees the skb when enqueue returns this permanent error.

EPSS 0.51% · 42.3th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.51%
42.3th percentile

Affected Products

VendorProductVersions
LinuxLinuxfce8a7bb5b4bfb8a27324703fd5b002ee9247e90, fce8a7bb5b4bfb8a27324703fd5b002ee9247e90, fce8a7bb5b4bfb8a27324703fd5b002ee9247e90
LinuxLinux3.9, 0, 5.10.270
linuxlinux_kernel3.9, 3.9, 3.9
LinuxLinuxfce8a7bb5b4bfb8a27324703fd5b002ee9247e90, fce8a7bb5b4bfb8a27324703fd5b002ee9247e90, fce8a7bb5b4bfb8a27324703fd5b002ee9247e90

Timeline

  • Sep 11, 2026 CVE Published
  • Sep 12, 2026 EPSS Score
  • Sep 12, 2026 Coalition ESS Score
  • Sep 13, 2026 EPSS Score
  • Sep 14, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›