Out-of-bounds read in Linux kernel - CVE-2026-80779
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to an out-of-bounds read in the Ionic network driver RX queue initialization logic when initializing a dedicated hardware timestamp receive queue. A local user can trigger XDP_TX processing on the affected receive queue to cause memory corruption.
The dedicated hardware timestamp receive queue does not have a corresponding normal transmit queue partner.
Affected software
How to mitigate CVE-2026-80779
External References
- https://git.kernel.org/stable/c/39fc615e355b65b8d43be30da57aa95ae6eaf688
- https://git.kernel.org/stable/c/881a805a8029ba48c0ce81c6674910f8d83f7afb
- https://git.kernel.org/stable/c/d92255b405fb6f5acca408239ccd742e0a42c9cb
- https://git.kernel.org/stable/c/ea081b4435515ac7177eb598a3c0678d1b9e7911
- https://git.kernel.org/stable/c/f3868046e8e2e761d4d943a232bd109ff22a7d5b