From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5D72B581259 for ; Fri, 11 Sep 2026 19:50:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156219; cv=none; b=F63KBNQKTnEv2Jpkqg/EpW9gajHTol3jR17e9eXqPc/ZqovwkLUO4WdRmQdwHjq033KxROouZ1cb5MVYPNAIu8zdzPM3VnF9HPuKz9NbtHWRDq79foELzoeiBDVIcINUiC9bsntG+atycUPe8AJ+BPvs8brgx1ZWolWRHU0txU8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789156219; c=relaxed/simple; bh=NcU66QqmD90V5OM9VKlN0ay61st/AO1fd6NcjLDN5GM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=e0oSGSpMFf+1J1W/pQ6mh1QTGocnSYyDgM8SsRj9lbzrC8+kDi9cnSXcGHbl7bIdD+5FCUc7FFGfiENz7GlOjJ0xjbIRvTco9qPuE1fHKW3zkCWFuTo1isu0OSlwpu5c/RHRjEPAjdIALlciZYsAnp8z47HatPDnBaZgicrbBqc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=djvnAILv; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="djvnAILv" Received: by smtp.kernel.org (Postfix) with ESMTPSA id EF3A21F00893; Fri, 11 Sep 2026 19:50:07 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789156208; bh=q5dyxx3V6ZzCHeVLU6kbbNahcwk3VsY7r2GPlagGj1s=; h=From:To:Cc:Subject:Date:Reply-To; b=djvnAILv1ALf3+AzO8hXdyHVHnjsTj5KjgMTyfmhnM0xaFl7iptMnatcQ8EhHXcyi dm1Jv36PodSU8RYgY6NlMUkMCwsHpfvAzY4VdmDQsc/7sk4txt9D8Tm7A7F52mkwmW AdICUsYEsqIsMvPDNFy1wFUNKkEIg0y9CZcqvw60= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80990: net: thunderbolt: Release the Rx HopID that was handed out on mismatch Date: Fri, 11 Sep 2026 21:41:36 +0200 Message-ID: <2026091148-CVE-2026-80990-b23d@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=2817; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=oOkQKgADiv8HLHzwnVUos1ZNfUD5gfThktPQwq6fFG8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFlLIh1UTTUFpTLyP25O6AjRP2Q/x4PTwv/kHOvmSpXUB weZWbg7YlkYBJkYZMUUWb5s4zm6v+KQopeh7WmYOaxMIEMYuDgFYCLlggzz7FNelK14YhQ/eVXc orMLWzhmsJStY1jQkLoz8a1PtZVdcNck2/qtpwRXdq0BAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id as a failure and returns without releasing what it got, so that allocation stays live for the rest of the XDomain connection with nothing left holding a reference to it. Release the id when it is not the one we asked for, the same way the error unwind at the end of the function releases the expected one. The Linux kernel CVE team has assigned CVE-2026-80990 to this issue. Affected and fixed versions =========================== Issue introduced in 5.13 with commit 180b0689425c6fb2b35e69a3316ee38371a782df and fixed in 6.12.109 with commit 9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0 Issue introduced in 5.13 with commit 180b0689425c6fb2b35e69a3316ee38371a782df and fixed in 6.18.50 with commit 61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea Issue introduced in 5.13 with commit 180b0689425c6fb2b35e69a3316ee38371a782df and fixed in 7.2.4 with commit 1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1 Issue introduced in 5.13 with commit 180b0689425c6fb2b35e69a3316ee38371a782df and fixed in 7.3-rc1 with commit 2f1463554d0561a2fead81e3888604e5c1125e29 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80990 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/net/thunderbolt/main.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0 https://git.kernel.org/stable/c/61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea https://git.kernel.org/stable/c/1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1 https://git.kernel.org/stable/c/2f1463554d0561a2fead81e3888604e5c1125e29