{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80987","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.811Z","datePublished":"2026-09-11T19:42:45.574Z","dateUpdated":"2026-09-14T11:59:28.875Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-14T11:59:28.875Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nNTB: ntb_transport: Reject oversized TX buffers\n\nntb_process_tx() handles an oversized buffer by calling tx_handler()\nwith a NULL data pointer and returning success. ntb_netdev therefore\nneither frees the skb in its completion callback nor takes its enqueue\nerror path, leaking it.\n\nReject oversized buffers in ntb_transport_tx_enqueue() before acquiring\na queue entry and return -EMSGSIZE. The caller retains ownership of the\nbuffer, and the preceding netdev patch frees the skb when enqueue\nreturns this permanent error."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - ntb_transport_tx_enqueue() is reached from ntb_netdev_start_xmit() on the NTB virtual Ethernet device; in dual-controller/cluster deployments that interconnect carries routed or 802.1Q traffic, so a remote peer can induce full-MTU egress (software VLAN insertion adds VLAN_HLEN past the transport payload limit) without local access.\nAC:L - Any TX buffer longer than tx_max_frame minus the payload header deterministically takes the oversized path; VLAN devices default to the lowerdev MTU so tagged full-size frames always exceed the limit, and AF_PACKET allows MTU+VLAN_HLEN, with no race or uncontrolled layout.\nPR:N - The netdev TX path has no authentication or capability check; once the NTB link is up, any host exchanging traffic over the interconnect or a VLAN/service on it can cause oversized transmits without credentials on the victim.\nUI:N - Oversized frames are transmitted by the kernel networking stack during ordinary packet egress; no victim action such as mounting a device or opening a file is required.\nS:U - The defect leaks sk_buff memory on the transmitting host inside the same kernel authority; it is not a VM escape, IOMMU/DMA bypass, or corruption of the peer host over the NTB link.\nC:N - The oversized path never copies payload bytes and does not free or reuse the skb, so there is no out-of-bounds read, use-after-free, or other information-disclosure primitive.\nI:N - ntb_process_tx() refuses to DMA or memcpy an oversized buffer and only invokes the completion callback with a NULL pointer, so there is no out-of-bounds write, heap corruption, or control-flow hijacking.\nA:H - Enqueue returns success while the TX handler is called with a NULL skb and skips kfree, permanently leaking one sk_buff (and its pages/socket accounting) per oversized transmit; repeating this exhausts kernel memory and causes OOM denial of service."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ntb/ntb_transport.c"],"versions":[{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"4890152a3069f5cb58cc24b08cfd5fe95e568fa1","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"668aa3238548584ca9772da9cf43ae8c2389bbf1","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"9b0fa8a9e1057614a533cc3f18b17f82aab028d8","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"b6db88cde0fb5c3bd2d3cd2bebcc06b5ce146e88","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"a7f22105a7df8c7fd74d0af27ace6fa94fe03d87","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"6b6bbc6c878d64eacc60877df49fce7b1b6a08d0","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"75a604e9f1cfdebda421062fdf42225ca32154cd","status":"affected","versionType":"git"},{"version":"fce8a7bb5b4bfb8a27324703fd5b002ee9247e90","lessThan":"a4f2387db6f1cc2f03abba7f3a6807ad61e26ff7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/ntb/ntb_transport.c"],"versions":[{"version":"3.9","status":"affected"},{"version":"0","lessThan":"3.9","status":"unaffected","versionType":"semver"},{"version":"5.10.270","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.221","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.188","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.157","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.109","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.50","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.4","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.10.270"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"5.15.221"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.1.188"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.6.157"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.12.109"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"6.18.50"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.2.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.9","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/4890152a3069f5cb58cc24b08cfd5fe95e568fa1"},{"url":"https://git.kernel.org/stable/c/668aa3238548584ca9772da9cf43ae8c2389bbf1"},{"url":"https://git.kernel.org/stable/c/9b0fa8a9e1057614a533cc3f18b17f82aab028d8"},{"url":"https://git.kernel.org/stable/c/b6db88cde0fb5c3bd2d3cd2bebcc06b5ce146e88"},{"url":"https://git.kernel.org/stable/c/a7f22105a7df8c7fd74d0af27ace6fa94fe03d87"},{"url":"https://git.kernel.org/stable/c/6b6bbc6c878d64eacc60877df49fce7b1b6a08d0"},{"url":"https://git.kernel.org/stable/c/75a604e9f1cfdebda421062fdf42225ca32154cd"},{"url":"https://git.kernel.org/stable/c/a4f2387db6f1cc2f03abba7f3a6807ad61e26ff7"}],"title":"NTB: ntb_transport: Reject oversized TX buffers","x_generator":{"engine":"bippy-1.2.0"}}}}