Description
In the Linux kernel, the following vulnerability has been resolved:

net: thunderbolt: Mark the connection down when bringing it up fails

Every failure path in tbnet_connected_work() undoes its own work and
returns without clearing login_sent, so the connection still looks
established. The next tbnet_tear_down() therefore takes its main branch
and repeats a teardown that already happened: it stops rings that are
already stopped, which is a dev_WARN() and fatal under panic_on_warn,
and it releases net->remote_transmit_path even on the HopID mismatch
path, where this connection never owned that id, silently freeing one
that someone else is still using.

Clear login_sent on those paths. That is enough for tbnet_tear_down() to
leave the unwound state alone, and login_received has to stay set: it
records that the peer has logged in and carries the transmit path it gave
us, which nothing on this side can make the peer send again. Two things
change beyond keeping the teardown out of the way: the logout request in
that block is no longer sent, and the peer's next login request now
re-queues our login work rather than connected_work, giving the
connection a fresh login instead of a retry on stale state.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (kernel crash)
Action: Patch Immediately
AI Analysis

Impact

The Linux kernel thunderbolt networking driver contains a flaw. When establishing a connection fails, the flag that indicates a login request has been sent is not reset, leading the tear‑down routine to operate on resources that are already released. This condition triggers a dev_WARN that escalates to a kernel panic under panic_on_warn. The driver also frees a remote transmit path it never owned, silently corrupting memory that may still be in use by other subsystems. The result is a kernel crash or subtle memory corruption that could otherwise facilitate further exploitation.

Affected Systems

All Linux kernel builds that include the thunderbolt networking driver prior to the patch that clears the login_sent flag on failure paths. This includes many distribution kernels and custom builds that ship an older thunderbolt driver. No specific release range is listed, so any kernel version that contains the unpatched code can be affected.

Risk and Exploitability

The CVSS score of 8.8 highlights high severity, while the EPSS score of <1% signals extremely low current exploitation likelihood. The vulnerability is not present in CISA's KEV catalog. An attacker would normally require local or privileged access to trigger thunderbolt connections, and the crash is deterministic once the fault condition is met. The low EPSS suggests that exploitation is unlikely at present, but the high severity warrants prompt remediation.

Generated by OpenCVE AI on September 21, 2026 at 01:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit clearing the login_sent flag on failure paths.
  • If a patch cannot be applied immediately, disable thunderbolt networking by unloading the thunderbolt_net module or adding a blacklist entry such as "blacklist thunderbolt_net" in /etc/modprobe.d/.
  • Reboot the system to ensure any existing thunderbolt session state is cleared and the defect cannot be exercised.

Generated by OpenCVE AI on September 21, 2026 at 01:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1341
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Mark the connection down when bringing it up fails Every failure path in tbnet_connected_work() undoes its own work and returns without clearing login_sent, so the connection still looks established. The next tbnet_tear_down() therefore takes its main branch and repeats a teardown that already happened: it stops rings that are already stopped, which is a dev_WARN() and fatal under panic_on_warn, and it releases net->remote_transmit_path even on the HopID mismatch path, where this connection never owned that id, silently freeing one that someone else is still using. Clear login_sent on those paths. That is enough for tbnet_tear_down() to leave the unwound state alone, and login_received has to stay set: it records that the peer has logged in and carries the transmit path it gave us, which nothing on this side can make the peer send again. Two things change beyond keeping the teardown out of the way: the logout request in that block is no longer sent, and the peer's next login request now re-queues our login work rather than connected_work, giving the connection a fresh login instead of a retry on stale state.
Title net: thunderbolt: Mark the connection down when bringing it up fails
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:31.013Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80989

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.730

Modified: 2026-09-14T13:18:53.647

Link: CVE-2026-80989

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:46Z

Links: CVE-2026-80989 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:00:09Z

Weaknesses
  • CWE-1341

    Multiple Releases of Same Resource or Handle