Answer in brief
CVE-2026-80866 records a Unknown severity vulnerability in tipc: avoid busy looping in tipc_exit_net(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04c26faa51d1e2fe71cf13c45791f5174c37f986 <522d1d950b9e3b68190a6de7534827c8dccedb73 || >=04c26faa51d1e2fe71cf13c45791f5174c37f986 <c1481c94e74c955e0448ddf46b8615a44d840c1e || d1f76dfadaf8f47ed1753f97dbcbd41c16215ffa || 5195ec5e365a2a9331bfeb585b613a6e94f98dba || b9f5b7ad4ac3af006443f535b1ce7bff1d130d7d || >=5.4.124 <5.5 || >=5.10.42 <5.11 || >=5.12.9 <5.13 | 522d1d950b9e3b68190a6de7534827c8dccedb73, c1481c94e74c955e0448ddf46b8615a44d840c1e, 5.5, 5.11, 5.13 |
| Linux/Linuxgeneric | 5.13 | Not reported |
Published upstream
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 4, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 4, 2026
In the Linux kernel, the following vulnerability has been resolved: tipc: avoid busy looping in tipc_exit_net() Blamed commit introduced a busy-wait loop in tipc_exit_net() to wait for pending UDP bearer cleanup works to complete: while (atomic_read(&tn->wq_count)) cond_resched(); This loop can busy-wait for a long time if cond_resched() is a NOP. This typically happens if the netns exit is executed by a high priority task, or under kernels configured without preemption (CONFIG_PREEMPT_NONE). In such cases, it wastes CPU cycles and can lead to soft lockups. Fix this by replacing the busy loop with wait_var_event(), allowing the thread to sleep properly until the work queue count reaches zero. Accordingly, update cleanup_bearer() to use atomic_dec_and_test() and wake_up_var() to wake up the waiter when the count drops to zero. This uses the global wait queue hash table, avoiding the need to bloat struct tipc_net with a wait_queue_head_t. The atomic_dec_and_test() provides the necessary memory barrier to ensure the wakeup is not missed.
Quoted source text, attributed separately from HOL analysis.