Incomplete Internal State Distinction in Linux kernel - CVE-2026-80989
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper connection state management in tbnet_connected_work() when handling a failed connection setup followed by connection teardown. A remote attacker can trigger a failed connection setup followed by connection teardown to cause a denial of service.
When panic_on_warn is enabled, stopping already stopped rings can be fatal.