Junglewise Threat Intelligence

CVE-2026-80995: Linux kernel MCTP use-after-free in route lookup

CVE-2026-80995 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MCTP (Management Component Transport Protocol) networking stack contains a use-after-free vulnerability in route lookup operations. An unprivileged local user can trigger this flaw through the MCTP socket interface, potentially causing kernel crashes or data corruption. This vulnerability affects systems running vulnerable kernel versions and could impact reliability and security of networked MCTP devices.

Technical details

The vulnerability is a use-after-free in the mctp_route_lookup() function in net/mctp/route.c. The function accesses rt->dev without holding a reference, allowing the device to be concurrently deallocated via mctp_dev_put() which calls kfree() on mdev->addrs. Subsequently, mctp_dev_saddr() attempts to read rt->dev->addrs[0], triggering a KASAN slab-use-after-free error. The flaw is reachable by unprivileged local AF_MCTP users on the receive/forwarding path without requiring CAP_NET_RAW. The fix adds refcount_inc_not_zero() to safely pin the device before use and properly releases the reference after the destination has taken its own, preventing concurrent deallocation.

Affected products

  • Linux Linux kernel multiple versions (patched via commits 408da1df18116c971c3392e21e50586688cd3fbf and cc561f8af25586300c2f9d285babb163b866b293)

Timeline

  • 2026-09-11: disclosed: CVE-2026-80995 published on NVD
  • 2026-08-20: patched: Fix committed to mainline by Jakub Kicinski
  • 2026-09-07: patched: Fix backported to stable kernels by Greg Kroah-Hartman

References

Related threats