Release of invalid pointer or reference in Linux kernel - CVE-2026-80790
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to trigger an invalid memory free.
The vulnerability exists due to improper pointer handling in nvmet_fc_alloc_ls_iodlist() when handling request-buffer allocation or response-buffer DMA mapping failures while initializing the LS IOD array. A local user can create a target port under these failure conditions to trigger an invalid memory free.
Affected software
How to mitigate CVE-2026-80790
External References
- https://git.kernel.org/stable/c/1a8f007faefe8c226ec65896589f8d59b0a8d5a5
- https://git.kernel.org/stable/c/371fb1bf902adaa59be32bd7e904a5317e604fd0
- https://git.kernel.org/stable/c/449e9c4f8db84ad9d9bb288029b230bcf590faa2
- https://git.kernel.org/stable/c/8bce9cd08aae4283badf8ddc11fbb6f57b75a81e
- https://git.kernel.org/stable/c/94334ea92f4d7535f66f86e33681efa94827eddc
- https://git.kernel.org/stable/c/b189c6e408896ccc23d2e76d7738847cdebf1532
- https://git.kernel.org/stable/c/ba98d6796d12258e837ece065d2ecb59d76ce4ff
- https://git.kernel.org/stable/c/bb9489f0dce58da730d3479588d6710d7a2c1b45
- https://git.kernel.org/stable/c/d094582cce9c08516d714e7436a8f3b9211dda90