Answer in brief
CVE-2026-80988 records a Unknown severity vulnerability in NTB: ntb_transport: Fail TX enqueue when the QP link is down. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f195a1a6fe416882984f8bd6c61afc1383171860 <5eca0d899a3be661a7e2caaaa7467a6fa15d756c || >=f195a1a6fe416882984f8bd6c61afc1383171860 <894e136b432da75c0352c80299807a5c4b04f167 || >=f195a1a6fe416882984f8bd6c61afc1383171860 <89177732fe1653bbfef10cf5d99bf20cf57762c2 || >=f195a1a6fe416882984f8bd6c61afc1383171860 <873ce713fef5dde0939220f04f3484ec86a16fba || aa6d6ed213b62cbdb09ea32abbfa085dd987a0c9 || a8986a61ebee0b54c5d648444fbae09bd1c6dcd2 || 94491412a2afc8a5aea4c5b455aed86d3486f0b1 || 3cfdc448e8bfa8a7eaa5af87f357330566124b78 || bfa051f650a7708183bd86901ca4645dcf88c486 || 4f4af6b8b7a23fa37decaf43b55403e6bfd8e219 || c2cd5d993f57f819d46fe62387d3cc34d8468e60 || 449b1978d4e50b14b2a4de3a26d0b074593926a3 || >=4.14.326 <4.15 || >=4.19.295 <4.20 || >=5.4.257 <5.5 || >=5.10.195 <5.11 || >=5.15.132 <5.16 || >=6.1.53 <6.2 || >=6.4.16 <6.5 || >=6.5.3 <6.6 | 5eca0d899a3be661a7e2caaaa7467a6fa15d756c, 894e136b432da75c0352c80299807a5c4b04f167, 89177732fe1653bbfef10cf5d99bf20cf57762c2, 873ce713fef5dde0939220f04f3484ec86a16fba, 4.15, 4.20, 5.5, 5.11, 5.16, 6.2, 6.5, 6.6 |
| Linux/Linuxgeneric | 6.6 | Not reported |
Published upstream
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 11, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 11, 2026
In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is down, but it only returns 0 without consuming the packet. Zero means success by this function's contract, so ntb_netdev reports NETDEV_TX_OK and forgets the skb: nothing queued it, nothing frees it, and it leaks, one skb for every transmit racing a link-down. Return -ENOLINK instead, restoring the contract that a non-zero return leaves the buffer owned by the caller. With the preceding patch, ntb_netdev frees the skb on non-retryable enqueue failures and returns NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking or entering a busy retry loop.
Quoted source text, attributed separately from HOL analysis.