Answer in brief
CVE-2026-80980 records a Unknown severity vulnerability in net/smc: stop killed, freed and out_of_sync sharing a byte. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b286a0651e4404ab96cdfdcdad8a839a26b3751e <313f79149eb337411c64e2c247234b62ef9a3cb9 || >=b286a0651e4404ab96cdfdcdad8a839a26b3751e <2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec || >=b286a0651e4404ab96cdfdcdad8a839a26b3751e <db51a8658c11a82432b64999519a269c3aabb447 | 313f79149eb337411c64e2c247234b62ef9a3cb9, 2cb7a8d64b7e8ccdc69bbe48fe9c4eaa79c33aec, db51a8658c11a82432b64999519a269c3aabb447 |
| Linux/Linuxgeneric | 5.8 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: net/smc: stop killed, freed and out_of_sync sharing a byte The three connection state flags are single-bit bitfields, so they occupy one byte of struct smc_connection and every store to one is a read-modify-write of the other two: u8 killed : 1; u8 freed : 1; u8 out_of_sync : 1; They are not written under a common lock. smc_cdc_msg_validate() sets out_of_sync from the receive tasklet, while smc_conn_kill() sets killed from process context under lock_sock(), and the receive path does not defer to the backlog when the socket is owned -- smc_cdc_msg_recv() takes only bh_lock_sock(). Give each flag its own byte so a store no longer touches its neighbours. All readers test them as booleans and are unchanged. struct smc_connection grows by two bytes.
Quoted source text, attributed separately from HOL analysis.