CVE-2026-80779
N/A
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
net/ionic: avoid OOB TX partner lookup for hwstamp RXQ
The dedicated hardware timestamp RX queue is allocated with q->index equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only contains the regular queue pairs, so using that index to set rxq->partner can read one entry past txqcqs[] and then write through the derived pointer. Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue has no TX partner.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 8eeed8373e1cca836799bf8e4a05cffa8e444908 < 881a805a8029ba48c0ce81c6674910f8d83f7afb | affected |
| Linux | Linux | 8eeed8373e1cca836799bf8e4a05cffa8e444908 < 39fc615e355b65b8d43be30da57aa95ae6eaf688 | affected |
| Linux | Linux | 8eeed8373e1cca836799bf8e4a05cffa8e444908 < f3868046e8e2e761d4d943a232bd109ff22a7d5b | affected |
| Linux | Linux | 8eeed8373e1cca836799bf8e4a05cffa8e444908 < ea081b4435515ac7177eb598a3c0678d1b9e7911 | affected |
| Linux | Linux | 8eeed8373e1cca836799bf8e4a05cffa8e444908 < d92255b405fb6f5acca408239ccd742e0a42c9cb | affected |
| Linux | Linux | 6.9 | affected |
| Linux | Linux | 0 < 6.9 | unaffected |
| Linux | Linux | 6.12.106 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.47 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.11 <= 7.1.* | unaffected |
| Linux | Linux | 7.2.1 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/881a805a8029ba48c0ce81c6674910f8d83f7afb
- https://git.kernel.org/stable/c/39fc615e355b65b8d43be30da57aa95ae6eaf688
- https://git.kernel.org/stable/c/f3868046e8e2e761d4d943a232bd109ff22a7d5b
- https://git.kernel.org/stable/c/ea081b4435515ac7177eb598a3c0678d1b9e7911
- https://git.kernel.org/stable/c/d92255b405fb6f5acca408239ccd742e0a42c9cb
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.