Junglewise Threat Intelligence

CVE-2026-80609: Linux kernel qede driver out-of-bounds read in TPA processing

CVE-2026-80609 · Severity: critical · CVSS 9.8 · Published 2026-08-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's qede Ethernet driver contains a logic error in how it processes network packet completion queue entries during TCP packet aggregation (TPA). An attacker could trigger an out-of-bounds memory read by crafting specific network packets, potentially leading to information disclosure or kernel crash and denial of service.

Technical details

The vulnerability exists in the qede network driver's TPA (TCP Packet Aggregation) completion handlers—specifically in the qede_tpa_cont() and qede_tpa_end() functions in drivers/net/ethernet/qlogic/qede/qede_fp.c. The vulnerable code checks array bounds (i < ARRAY_SIZE(cqe->len_list)) after accessing the array element (cqe->len_list[i]) in the loop condition, creating a time-of-check-time-of-use (TOCTOU) race that allows out-of-bounds reads. A remote attacker can send specially crafted network packets that trigger the TPA code path and cause the driver to read beyond allocated memory. The fix reorders the loop condition to check the array bounds before accessing the element, eliminating the vulnerability. A patch was merged upstream and backported to stable kernel branches.

Affected products

  • Linux Linux Kernel Multiple kernel versions (see git history from linux-2.6.11.y through linux-7.2.y)

Timeline

  • 2026-08-28: disclosed: CVE-2026-80609 published
  • 2026-06-23: patched: Patch authored by Matvey Kovalev
  • 2026-07-24: patched: Patch committed and backported to stable kernel trees

References

Related threats