Description
In the Linux kernel, the following vulnerability has been resolved:

NTB: ntb_transport: Reject oversized TX buffers

ntb_process_tx() handles an oversized buffer by calling tx_handler()
with a NULL data pointer and returning success. ntb_netdev therefore
neither frees the skb in its completion callback nor takes its enqueue
error path, leaking it.

Reject oversized buffers in ntb_transport_tx_enqueue() before acquiring
a queue entry and return -EMSGSIZE. The caller retains ownership of the
buffer, and the preceding netdev patch frees the skb when enqueue
returns this permanent error.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via memory exhaustion
Action: Patch
AI Analysis

Impact

An oversized transmit buffer sent through the NTB transport driver is mishandled by ntb_process_tx(): it passes a NULL data pointer to the handler and reports success, causing the associated socket buffer (skb) to remain allocated. Each instance of this bug leaks the skb, incrementally draining kernel memory. Over time a repeated injection of oversized buffers can exhaust memory, potentially leading to a kernel panic or forced reboot, thereby denying service to legitimate users.

Affected Systems

All Linux kernel builds that compile the NTB transport layer are vulnerable until the change that rejects oversized buffers in ntb_transport_tx_enqueue() is present. The description does not list specific distributions; based on the information, any distribution that ships the ntb module in its kernel, whether Debian, Red Hat, SUSE, or custom builds, is affected until a kernel update includes the fix.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, yet the EPSS score is below 1 %, implying a very low exploitation probability. The likely attack vector requires local privileged access to the NTB driver to send oversized transmit buffers; remote exploitation or privilege escalation is not indicated in the description. Consequently, the risk profile is that of a memory‑exhaustion denial‑of‑service attack that has not been catalogued in CISA KEV.

Generated by OpenCVE AI on September 21, 2026 at 03:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to a release that implements the patch for ntb_transport_tx_enqueue, ensuring oversized TX buffers are rejected and the skb is freed.
  • If the NTB functionality is not needed for your system, unload the ntb module or add it to the blacklist to eliminate the vulnerable code path.
  • Modify any user‑space applications that transmit data via NTB to enforce strict buffer size limits that comply with the driver's accepted range, preventing accidental skb leaks.
  • Monitor kernel memory usage and log entries for signs of abnormal growth or repeated SKB leaks, and consider scheduling a planned reboot if memory pressure escalates before the patch is applied.

Generated by OpenCVE AI on September 21, 2026 at 03:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Reject oversized TX buffers ntb_process_tx() handles an oversized buffer by calling tx_handler() with a NULL data pointer and returning success. ntb_netdev therefore neither frees the skb in its completion callback nor takes its enqueue error path, leaking it. Reject oversized buffers in ntb_transport_tx_enqueue() before acquiring a queue entry and return -EMSGSIZE. The caller retains ownership of the buffer, and the preceding netdev patch frees the skb when enqueue returns this permanent error.
Title NTB: ntb_transport: Reject oversized TX buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:28.875Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80987

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.353

Modified: 2026-09-14T13:18:53.343

Link: CVE-2026-80987

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:45Z

Links: CVE-2026-80987 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:15:09Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime