PatchSiren cyber security CVE debrief
CVE-2026-80787 Linux CVE debrief
A use-after-free vulnerability was found in the Linux kernel's nvmet_pci_epf_exec_iod_work function. This issue occurs when the function submits an I/O command and then waits for it to complete. However, the command may complete asynchronously on another CPU, leading to a potential use-after-free error when accessing iod->data_len and iod->dma_dir after the command has completed.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-04
- Original CVE updated
- 2026-09-04
- Advisory published
- 2026-09-04
- Advisory updated
- 2026-09-04
Who should care
Linux kernel maintainers, users, and administrators should assess exposure and prioritize verification of affected systems. This includes reviewing Linux kernel versions, verifying system configurations for nvmet_pci_epf_exec_iod_work usage, and applying patches if available. Additionally, operators, platform administrators, vulnerability management teams, and security teams should be aware of the potential risks and take necessary precautions.
Why it matters
A use-after-free vulnerability was found in the Linux kernel's nvmet_pci_epf_exec_iod_work function. This issue may lead to potential security risks if not addressed.
- Verify Linux kernel versions for potential exposure
- Assess system configurations for nvmet_pci_epf_exec_iod_work usage
- Apply patch if available to prevent potential use-after-free errors
Technical summary
The vulnerability is caused by a use-after-free error in the nvmet_pci_epf_exec_iod_work function. This function submits an I/O command and waits for it to complete. However, the command may complete asynchronously on another CPU, leading to a potential use-after-free error when accessing iod->data_len and iod->dma_dir after the command has completed. The issue was resolved by referring to iod->data_len and iod->dma_dir before calling req->execute().
Defensive priority
Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.
Recommended defensive actions
- Review Linux kernel versions for potential exposure
- Verify system configurations for nvmet_pci_epf_exec_iod_work usage
- Apply patch if available to prevent potential use-after-free errors
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The issue was resolved by referring to iod->data_len and iod->dma_dir before calling req->execute(). This change prevents the use-after-free error by ensuring that these fields are accessed before the iod is potentially freed. Linux kernel maintainers and users should verify the patch and assess exposure to ensure system security. Additional verification tasks include reviewing system configurations for nvmet_pci_epf_exec_iod_work usage and applying the patch if available. The CVE record was published on 2026-09-04T16:18:04.710Z and 3
Sources and references
Verified primary and authoritative sources
-
CVE-2026-80787 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-80787
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-80787 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80787
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1ed1eeaef55cebf2d74b3ef104c20bdab719b165
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/20be486d1c225402b067391e72ff5b0dd8ebff76
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c9e9bb757971485b4e8414b1744507af186d72c9
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/cede8d2852570c79b9bbb9527255ae9ed3317b82
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.