UBUNTU-CVE-2026-80779
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-80779
Summary:
Details: In the Linux kernel, the following vulnerability has been resolved: net/ionic: avoid OOB TX partner lookup for hwstamp RXQ The dedicated hardware timestamp RX queue is allocated with q->index equal to lif->ionic->nrxqs_per_lif. The normal txqcqs array only contains the regular queue pairs, so using that index to set rxq->partner can read one entry past txqcqs[] and then write through the derived pointer. Only link RX/TX partners for normal queue-pair indexes. Leave the hwstamp RX queue unpaired, and make the XDP_TX path abort cleanly if an RX queue has no TX partner.
References: https://ubuntu.com/security/CVE-2026-80779, https://www.cve.org/CVERecord?id=CVE-2026-80779, https://git.kernel.org/linus/d92255b405fb6f5acca408239ccd742e0a42c9cb
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
