Answer in brief
CVE-2026-80790 records a Unknown severity vulnerability in nvmet-fc: fix invalid free in LS IOD error path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <b189c6e408896ccc23d2e76d7738847cdebf1532 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <449e9c4f8db84ad9d9bb288029b230bcf590faa2 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <1a8f007faefe8c226ec65896589f8d59b0a8d5a5 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <d094582cce9c08516d714e7436a8f3b9211dda90 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <371fb1bf902adaa59be32bd7e904a5317e604fd0 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <8bce9cd08aae4283badf8ddc11fbb6f57b75a81e || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <bb9489f0dce58da730d3479588d6710d7a2c1b45 || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <94334ea92f4d7535f66f86e33681efa94827eddc || >=c53432030d86429dc9fe5adc3d68cb9d1343b0b2 <ba98d6796d12258e837ece065d2ecb59d76ce4ff | b189c6e408896ccc23d2e76d7738847cdebf1532, 449e9c4f8db84ad9d9bb288029b230bcf590faa2, 1a8f007faefe8c226ec65896589f8d59b0a8d5a5, d094582cce9c08516d714e7436a8f3b9211dda90, 371fb1bf902adaa59be32bd7e904a5317e604fd0, 8bce9cd08aae4283badf8ddc11fbb6f57b75a81e, bb9489f0dce58da730d3479588d6710d7a2c1b45, 94334ea92f4d7535f66f86e33681efa94827eddc, ba98d6796d12258e837ece065d2ecb59d76ce4ff |
| Linux/Linuxgeneric | 4.10 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: fix invalid free in LS IOD error path nvmet_fc_alloc_ls_iodlist() advances iod while initializing the LS IOD array. If an rqstbuf allocation or response buffer DMA mapping fails, the unwind loop decrements iod past the start of the array. The final kfree(iod) therefore frees an address before the allocated object. This can be reproduced with nvme-fcloop and failslab by setting fail-nth to 6 before creating a target port. KASAN reports: BUG: KASAN: invalid-free in nvmet_fc_register_targetport Free of addr ffff88816cf8ff48 by task nvmet_fail_nth/9552 Free the original allocation base stored in tgtport->iod instead. With this fix applied, the same sysfs write with fail-nth=6 returns -ENOMEM without any KASAN report.
Quoted source text, attributed separately from HOL analysis.