PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-80995 Linux CVE debrief

A use-after-free vulnerability exists in the Linux kernel's net: mctp module. The issue arises from mctp_route_lookup() using rt->dev without holding a reference to it, allowing the route's device to be torn down concurrently by an unprivileged local AF_MCTP user on the receive/forwarding path, potentially leading to system instability or crashes. This vulnerability requires immediate attention from Linux kernel developers, maintainers, and users. Affected systems should apply the provided kernel patches as soon as possible to prevent potential exploitation. The vulnerability was resolved by taking a reference with refcount_inc_not_zero() before touching rt->dev, skipping a device

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-11
Original CVE updated
2026-09-11
Advisory published
2026-09-11
Advisory updated
2026-09-11

Who should care

Linux kernel developers and maintainers, Linux distribution vendors, users of Linux-based systems that utilize the AF_MCTP protocol, and security teams responsible for vulnerability management and remediation prioritization. These stakeholders should review and apply patches, monitor for exploitation attempts, and assess the potential impact on their systems and infrastructure.

Why it matters

This use-after-free vulnerability in the Linux kernel's net: mctp module requires immediate attention from Linux kernel developers, maintainers, and users. The vulnerability can be exploited by an unprivileged local AF_MCTP user, and its successful exploitation could lead to a system crash or instability. Affected systems should apply the provided kernel patches as soon as possible to prevent potential exploitation.

  • Unprivileged local users may exploit this vulnerability to cause a denial-of-service (DoS) or potentially execute arbitrary code.
  • Successful exploitation could lead to a system crash or instability.
  • The vulnerability requires verification of affected versions and remediation priority from official sources.

Technical summary

The vulnerability exists in the Linux kernel's net: mctp module, specifically in the mctp_route_lookup() function. The function uses rt->dev without holding a reference to it, allowing the route's device to be torn down concurrently by an unprivileged local AF_MCTP user on the receive/forwarding path. This can be exploited to cause a denial-of-service (DoS) or potentially execute arbitrary code. The vulnerability requires verification of affected versions and remediation priority from official sources. The fix involves taking a reference with refcount_inc_not_zero() before touching rt->dev, skipping a device that is already dead, and dropping the reference once the destination has taken its own.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the provided kernel patches to ensure the vulnerability is addressed.
  • Monitor system logs for potential exploitation attempts.
  • Restrict access to the AF_MCTP protocol to only necessary users.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was resolved by taking a reference with refcount_inc_not_zero() before touching rt->dev, skipping a device that is already dead, and dropping the reference once the destination has taken its own.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-80995 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-80995

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-80995 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-80995

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/408da1df18116c971c3392e21e50586688cd3fbf

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/cc561f8af25586300c2f9d285babb163b866b293

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.