Out-of-bounds read in Linux kernel - CVE-2026-80609
Published: August 28, 2026
Vulnerability identifier: #VU146279
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80609
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an out-of-bounds read in the qede driver qede_tpa_cont and qede_tpa_end handling of cqe->len_list[] when processing crafted CQE data. A local user can trigger access past the end of the len_list array to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-80609
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/1aacefd074b5dcc99b8dbcd73e1c963ed5010110
- https://git.kernel.org/stable/c/6d203bdd227fca1787f8a80cf84b990936633c5a
- https://git.kernel.org/stable/c/6d46ab395803f162cdc50e8d346e5f1a4e766771
- https://git.kernel.org/stable/c/b17751a2ebc4aef3ce6be6f71ee8df92bf5ddfcd
- https://git.kernel.org/stable/c/bd3a6a083b408e96437dbd86ff543ba9ec3a788b
- https://git.kernel.org/stable/c/e30af53dca803893a29eb3bbe0539752ba435410
- https://git.kernel.org/stable/c/f9ba47fce5932c15891c89c60e76dfaca919cb8d