PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80861 Linux CVE debrief

A Linux kernel vulnerability allows an unaligned read access when a USB controller is inaccessible, leading to a kernel paging request fault. The issue arises when the xHCI host controller is unable to change its power state, yet still reaches the HCD probe path. To address this, the capability register should be read once, and if it returns an all-ones value, setup should be aborted with -ENODEV before deriving op_regs from it.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-04
Original CVE updated
2026-10-03
Advisory published
2026-09-04
Advisory updated
2026-10-03

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, and users of Linux-based systems with xHCI host controllers should review configurations and patches to ensure the fix is applied. Linux distribution vendors should update affected systems with the latest kernel version. Users of Linux-based systems with xHCI host controllers should monitor system logs for potential errors.

Why it matters

The vulnerability allows an unaligned read access when a USB controller is inaccessible, leading to a kernel paging request fault. Linux kernel developers and maintainers should review configurations and patches to ensure the fix is applied. Linux distribution vendors should update affected systems with the latest kernel version. Users of Linux-based systems with xHCI host controllers should monitor system logs for potential errors.

  • Verify Linux kernel configurations and patches to ensure the fix is applied
  • Monitor system logs for potential errors related to xHCI host controllers
  • Update affected systems with the latest kernel version

Technical summary

The Linux kernel's xHCI driver does not properly handle inaccessible USB controllers, leading to an unaligned read access and kernel paging request fault. This occurs when the xHCI host controller is unable to change its power state, yet still reaches the HCD probe path. To address this, the capability register should be read once, and if it returns an all-ones value, setup should be aborted with -ENODEV before deriving op_regs from it. Linux kernel developers and maintainers should review configurations and patches to ensure the fix is applied.

Defensive priority

Medium

Recommended defensive actions

  • Review Linux kernel configurations and patches to ensure the fix is applied
  • Verify that affected systems are updated with the latest kernel version
  • Monitor system logs for potential errors related to xHCI host controllers
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The vulnerability was introduced in the Linux kernel's xHCI driver. A Renesas uPD720201 controller that failed to power up still reached the HCD probe path, causing an unaligned read access. This issue arises when the xHCI host controller is unable to change its power state, yet still reaches the HCD probe path. The capability register should be read once, and if it returns an all-ones value, setup should be aborted with -ENODEV before deriving op_regs from it.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80861 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80861

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80861 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80861

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0b31744f70c5e06cce5fb660e02d057a3b9e0e37

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/301f4a3303b21ea959a8294518ee883710498ac2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/70706dbcf122940f4e3595d7ba1445004cc00074

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/78203d5b54a40f0e36196ebf31c9c7a380fc8811

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/bf84c6b0264947794fa783c324a6d874ca6657d8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c051f66b621695ad7c8438a9497d79e1f4f05edb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.