Executive brief
The Linux kernel's Thunderbolt networking driver contains a flaw in how it handles failed connection attempts. When a connection setup fails, the driver leaves internal state markers in a misleading condition, causing subsequent cleanup operations to repeat actions already performed or incorrectly release resources belonging to other connections, leading to system crashes or resource corruption.
Technical details
The vulnerability exists in the tbnet_connected_work() function in the Thunderbolt network driver (drivers/net/thunderbolt/main.c). When connection establishment fails at various points, the failure paths undo their work but fail to clear the login_sent flag, leaving the connection appearing as established. Subsequent teardown operations then repeat already-performed cleanup (stopping rings, releasing transmit paths) on stale state. In the HopID mismatch path, this can release a resource (remote_transmit_path) that the connection never owned, causing a use-after-free in other connections. The fix clears the login_sent flag on failure paths while preserving login_received state. The vulnerable code was introduced in commit e69b6c02b4c3 and affects kernel versions 5.13 and later. The patch is available and backported to stable branches.
Affected products
- Linux Linux kernel 5.13 and later
Timeline
- 2026-09-11: disclosed: CVE published on NVD
- 2026-08-17: patched: Patch committed upstream by Jakub Kicinski
- 2026-09-07: patched: Backported to stable kernel branches