Out-of-bounds write in Linux kernel - CVE-2026-80640
Published: August 28, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a buffer overflow in cxlctl_get_supported_features() in the cxl core feature handling code when processing supported feature entries. A local user can trigger the vulnerable code path to cause a denial of service.
The issue manifests as a fortify runtime assertion in the kernel.