CVE-2026-80988
Received Received - Intake

NTB Transport Link Down Packet Leak

Vulnerability report for CVE-2026-80988, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-14

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is down, but it only returns 0 without consuming the packet. Zero means success by this function's contract, so ntb_netdev reports NETDEV_TX_OK and forgets the skb: nothing queued it, nothing frees it, and it leaks, one skb for every transmit racing a link-down. Return -ENOLINK instead, restoring the contract that a non-zero return leaves the buffer owned by the caller. With the preceding patch, ntb_netdev frees the skb on non-retryable enqueue failures and returns NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking or entering a busy retry loop.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-14
Generated
2026-10-02
AI Q&A
2026-09-12
EPSS Evaluated
2026-09-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a flaw in the NTB (Non-Transparent Bridge) transport layer. When a queue pair (QP) link goes down, the function ntb_transport_tx_enqueue() incorrectly returns 0 (success) instead of an error code, causing packet leaks. The kernel then assumes the packet was successfully queued, leading to memory leaks as the skb (socket buffer) is never freed.

Detection Guidance

This vulnerability involves packet leaks in the Linux kernel's NTB (Non-Transparent Bridge) transport layer when a QP (Queue Pair) link is down. Detection requires checking for leaked skb (socket buffer) structures in kernel logs or memory dumps. Monitor for repeated NETDEV_TX_OK errors in system logs during link-down events. Use kernel tracing tools like ftrace or eBPF to track ntb_transport_tx_enqueue() calls returning 0 during link-down conditions.

Impact Analysis

This vulnerability can cause memory leaks in the Linux kernel, leading to gradual exhaustion of system memory. It may result in system instability, crashes, or degraded performance due to resource depletion. Systems using NTB for communication could experience packet loss or unexpected behavior during link-down events.

Compliance Impact

This vulnerability does not directly affect compliance with standards like GDPR or HIPAA. It involves a memory leak in the Linux kernel's NTB transport layer due to improper packet handling during link-down conditions, which is a reliability and resource management issue rather than a data protection or privacy concern.

Mitigation Strategies

Apply the kernel patch that changes the return value from 0 to -ENOLINK in ntb_transport_tx_enqueue() when the QP link is down. Update to a Linux kernel version that includes the fix (commit f195a1a6fe41 or later). If immediate patching is not possible, disable affected NTB transport interfaces until the update is applied to prevent packet leaks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80988. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart