PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80787 Linux CVE debrief

A use-after-free vulnerability was found in the Linux kernel's nvmet_pci_epf_exec_iod_work function. This issue occurs when the function submits an I/O command and then waits for it to complete. However, the command may complete asynchronously on another CPU, leading to a potential use-after-free error when accessing iod->data_len and iod->dma_dir after the command has completed.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-09-04
Advisory published
2026-09-04
Advisory updated
2026-09-04

Who should care

Linux kernel maintainers, users, and administrators should assess exposure and prioritize verification of affected systems. This includes reviewing Linux kernel versions, verifying system configurations for nvmet_pci_epf_exec_iod_work usage, and applying patches if available. Additionally, operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential risks and take necessary precautions.

Why it matters

A use-after-free vulnerability was found in the Linux kernel's nvmet_pci_epf_exec_iod_work function. This issue may lead to potential security risks if not addressed.

  • Verify Linux kernel versions for potential exposure
  • Assess system configurations for nvmet_pci_epf_exec_iod_work usage
  • Apply patch if available to prevent potential use-after-free errors

Technical summary

The vulnerability is caused by a use-after-free error in the nvmet_pci_epf_exec_iod_work function. This function submits an I/O command and waits for it to complete. However, the command may complete asynchronously on another CPU, leading to a potential use-after-free error when accessing iod->data_len and iod->dma_dir after the command has completed. The issue was resolved by referring to iod->data_len and iod->dma_dir before calling req->execute().

Defensive priority

Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.

Recommended defensive actions

  • Review Linux kernel versions for potential exposure
  • Verify system configurations for nvmet_pci_epf_exec_iod_work usage
  • Apply patch if available to prevent potential use-after-free errors
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The issue was resolved by referring to iod->data_len and iod->dma_dir before calling req->execute(). This change prevents the use-after-free error by ensuring that these fields are accessed before the iod is potentially freed. Linux kernel maintainers and users should verify the patch and assess exposure to ensure system security. Additional verification tasks include reviewing system configurations for nvmet_pci_epf_exec_iod_work usage and applying the patch if available. The CVE record was published on 2026-09-04T16:18:04.710Z and 3

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80787 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80787

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80787 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80787

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1ed1eeaef55cebf2d74b3ef104c20bdab719b165

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/20be486d1c225402b067391e72ff5b0dd8ebff76

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c9e9bb757971485b4e8414b1744507af186d72c9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cede8d2852570c79b9bbb9527255ae9ed3317b82

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.