CVE-2026-80989

8.8

Linux · Kernel

A logic error in the Linux kernel Thunderbolt networking driver fails to clear connection states during setup failures, potentially leading to kernel panics or resource mismanagement.

Executive summary

A flaw in the Linux kernel Thunderbolt networking subsystem allows for potential system instability or resource corruption when connection attempts fail, posing a significant risk to system availability.

Vulnerability

The vulnerability exists in the tbnet_connected_work function, where failure paths fail to properly clear the login_sent status. This unauthenticated flaw allows an attacker or a faulty device to trigger a repetitive teardown process, leading to a kernel warning or invalid memory management.

Business impact

The potential for a kernel panic poses a severe threat to system availability, particularly for critical infrastructure or server environments relying on Thunderbolt connectivity. With a CVSS score of 8.8, this vulnerability is classified as High, reflecting the risk of denial of service and potential memory corruption that could be leveraged to disrupt operations.

Remediation

Immediate Action: Update the Linux kernel to version 6.12.109, 6.18.50, 7.2.4, or later, as provided by your distribution vendor.

Proactive Monitoring: Monitor system logs for kernel warnings related to Thunderbolt networking or unexpected device teardown events.

Compensating Controls: Disable Thunderbolt networking interfaces if they are not required for current operations to eliminate the attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability presents a clear risk to system stability and uptime. IT administrators should prioritize patching the Linux kernel across all affected systems that utilize Thunderbolt networking. Testing the update in a staging environment is advised before full deployment to ensure compatibility with existing hardware configurations.

More Linux CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. Analyst report written
  4. Published in the daily brief high section

Sources