Junglewise Threat Intelligence

CVE-2026-80988: Linux kernel ntb_transport memory leak on link down

CVE-2026-80988 · Severity: info · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's NTB (Non-Transparent Bridge) transport driver has a memory leak in its packet transmission queue. When the inter-device link drops while a packet transmission is queued, the driver incorrectly signals success without properly handling the packet, causing it to be abandoned in memory and never freed. This results in incremental memory waste on systems using NTB for inter-device communication.

Technical details

The vulnerability is a resource leak in the ntb_transport_tx_enqueue() function within drivers/ntb/ntb_transport.c. When the QP (queue pair) link is down, the function returns 0 (success) without consuming or queuing the socket buffer (skb), violating the function's contract that a non-zero return means the caller retains ownership. The network device driver (ntb_netdev) interprets the success code and releases the skb, leaving nothing to free the packet data—one skb per transmission attempt races with link-down event. The fix changes the return value from 0 to -ENOLINK, restoring proper contract semantics. No authentication or special privilege is required; any caller attempting to transmit while the link is down triggers the leak.

Affected products

  • Linux Linux kernel multiple versions with ntb_transport driver

Timeline

  • 2026-09-11: disclosed
  • 2026-09-07: patched

References

Related threats