SB20260905176 - Out-of-bounds read in Linux kernel pensando ionic driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-80779)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds read in the Ionic network driver RX queue initialization logic when initializing a dedicated hardware timestamp receive queue. A local user can trigger XDP_TX processing on the affected receive queue to cause memory corruption.
The dedicated hardware timestamp receive queue does not have a corresponding normal transmit queue partner.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/39fc615e355b65b8d43be30da57aa95ae6eaf688
- https://git.kernel.org/stable/c/881a805a8029ba48c0ce81c6674910f8d83f7afb
- https://git.kernel.org/stable/c/d92255b405fb6f5acca408239ccd742e0a42c9cb
- https://git.kernel.org/stable/c/ea081b4435515ac7177eb598a3c0678d1b9e7911
- https://git.kernel.org/stable/c/f3868046e8e2e761d4d943a232bd109ff22a7d5b