Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80998

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-80998

Published: September 12, 2026


Vulnerability identifier: #VU149401
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80998
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper handling of an early return in the bnxt software UDP generic segmentation offload transmission path when processing UDP generic segmentation offload packets. A local user can trigger an early return while a transmit doorbell write is pending to cause a denial of service.


Affected software

Linux kernel

How to mitigate CVE-2026-80998

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins