Description
In the Linux kernel, the following vulnerability has been resolved:

NTB: ntb_transport: Fail TX enqueue when the QP link is down

Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to
make ntb_transport_tx_enqueue() drop packets submitted while the QP link
is down, but it only returns 0 without consuming the packet. Zero means
success by this function's contract, so ntb_netdev reports NETDEV_TX_OK
and forgets the skb: nothing queued it, nothing frees it, and it leaks,
one skb for every transmit racing a link-down.

Return -ENOLINK instead, restoring the contract that a non-zero return
leaves the buffer owned by the caller. With the preceding patch,
ntb_netdev frees the skb on non-retryable enqueue failures and returns
NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking
or entering a busy retry loop.
Published: 2026-09-11
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a contract violation in the Linux kernel component ntb_transport_tx_enqueue, where a commit intended to drop packets when a QP link is down incorrectly returns 0 instead of an error code. Returning zero signals success to the caller, causing ntb_netdev to report NETDEV_TX_OK while the packet is neither queued nor freed. As a result, each transmit operation that runs while the link is down leaks a socket buffer (skb), gradually exhausting kernel memory.

Affected Systems

All Linux distributions that ship the kernel without the f195a1a6fe41 commit are affected, regardless of distribution or patch level. The specific versions are not listed, so any kernel that predates the patch that restored the proper error return is considered vulnerable.

Risk and Exploitability

Based on the description, the most likely attack vector is local packet transmission to trigger the condition, as the function is invoked during normal network operations. An adversary could generate network traffic that races with a manual or automated link reset to cause repeated skb leaks. The moderate CVSS score of 4.1, combined with an EPSS score of less than 1% and absence from the CISA KEV catalog, suggests that active exploitation is unlikely, but a determined attacker could force resource exhaustion by repeatedly provoking the failure.

Generated by OpenCVE AI on September 21, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that changes ntb_transport_tx_enqueue to return –ENOLINK instead of zero, which addresses the improper memory handling identified as CWE-772 and stops skb leaks when the QP link is down.
  • If an immediate kernel upgrade is not possible, modify applications or network services to verify QP link status before transmitting packets, avoiding the scenario that triggers the fault.
  • Continuously monitor system memory usage for abnormal increases that may indicate lingering skb leaks, and set alert thresholds to detect a potential resource exhaustion scenario.

Generated by OpenCVE AI on September 21, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: NTB: ntb_transport: Fail TX enqueue when the QP link is down Commit f195a1a6fe41 ("ntb: Drop packets when qp link is down") meant to make ntb_transport_tx_enqueue() drop packets submitted while the QP link is down, but it only returns 0 without consuming the packet. Zero means success by this function's contract, so ntb_netdev reports NETDEV_TX_OK and forgets the skb: nothing queued it, nothing frees it, and it leaks, one skb for every transmit racing a link-down. Return -ENOLINK instead, restoring the contract that a non-zero return leaves the buffer owned by the caller. With the preceding patch, ntb_netdev frees the skb on non-retryable enqueue failures and returns NETDEV_TX_OK, so a packet racing with link-down is dropped without leaking or entering a busy retry loop.
Title NTB: ntb_transport: Fail TX enqueue when the QP link is down
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:29.941Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80988

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.480

Modified: 2026-09-14T13:18:53.493

Link: CVE-2026-80988

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:46Z

Links: CVE-2026-80988 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime