CVE-2026-80988
In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is down, but it only returns 0 without consuming the packet. Zero means success by this function's contract, so ntb_netdev reports NETDEV_TX_OK and forgets the skb: nothing queued it, nothing frees it, and it leaks, one skb for every transmit racing a link-down. Return -ENOLINK instead, restoring the contract that a non-zero return leaves the buffer owned by the caller. With the preceding patch, ntb_netdev frees the skb on non-retryable enqueue failures and returns NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking or entering a busy retry loop.
Affected versions
Linux kernel versions
5.10.195,
5.15.132,
6.1.53,
4.14.326,
4.19.295,
5.4.257,
6.4.16,
6.5.3,
6.6
and later are affected. Fixed in
5.10.270,
5.15.221,
6.1.188,
6.6.157,
6.12.109,
6.18.50,
7.2.4,
7.3-rc1
and their respective stable series.
References
8 totalFrequently asked questions
-
What is CVE-2026-80988?
CVE-2026-80988 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 5.10.195 onward and has been patched in 5.10.270, 5.15.221, 6.1.188 and others. CVE-2026-80988 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-80988?
Yes. CVE-2026-80988 has been patched. Fixed versions include 5.10.270, 5.15.221, 6.1.188 and others. If you are running Linux kernel 5.10.195 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-80988 actively exploited?
No. CVE-2026-80988 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.