Description
In the Linux kernel, the following vulnerability has been resolved:

net: thunderbolt: Release the Rx HopID that was handed out on mismatch

tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range()
as the lower bound, so a taken id is not an error there: the allocator
returns the next free one above it. tbnet_connected_work() asks for the
peer's transmit path, treats any other id as a failure and returns
without releasing what it got, so that allocation stays live for the rest
of the XDomain connection with nothing left holding a reference to it.

Release the id when it is not the one we asked for, the same way the
error unwind at the end of the function releases the expected one.
Published: 2026-09-11
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Resource Exhaustion / Denial of Service
Action: Apply Patch
AI Analysis

Impact

The Linux kernel Thunderbolt networking subsystem can allocate a HopID for XDomain connections and, if the requested identifier does not match the expected value, the ID is never released. This causes a permanent reservation of a finite resource. Repeated allocation failures over time exhaust the HopID pool, preventing new XDomain connections from being established and effectively disrupting network operations.

Affected Systems

All Linux kernel distributions where the Thunderbolt networking module is loaded. The vulnerability resides at the kernel level, affecting any distribution that ships with this code without the subsequent patch.

Risk and Exploitability

The CVSS score of 4.8 classifies the issue as moderate severity, and the EPSS score of less than one percent indicates a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need the ability to initiate repeated Thunderbolt XDomain connections to the target system. The precise attack vector is not specified in the data, but it can be inferred that it is limited to environments where Thunderbolt networking is active and potentially exposed to attackers.

Generated by OpenCVE AI on September 21, 2026 at 02:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the fix for CVE-2026-80990.
  • Disable or unload the Thunderbolt networking module to remove the vulnerability surface.
  • Implement monitoring for anomalous HopID allocation rates and consider imposing limits on concurrent XDomain connections to mitigate the impact of resource exhaustion.
  • Apply a kernel backport or manual patch if the latest release with the fix is not yet available.

Generated by OpenCVE AI on September 21, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-772
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Important


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch tb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range() as the lower bound, so a taken id is not an error there: the allocator returns the next free one above it. tbnet_connected_work() asks for the peer's transmit path, treats any other id as a failure and returns without releasing what it got, so that allocation stays live for the rest of the XDomain connection with nothing left holding a reference to it. Release the id when it is not the one we asked for, the same way the error unwind at the end of the function releases the expected one.
Title net: thunderbolt: Release the Rx HopID that was handed out on mismatch
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T11:59:32.077Z

Reserved: 2026-08-26T14:34:25.811Z

Link: CVE-2026-80990

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:05.867

Modified: 2026-09-14T13:18:53.787

Link: CVE-2026-80990

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-11T19:42:47Z

Links: CVE-2026-80990 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses
  • CWE-772

    Missing Release of Resource after Effective Lifetime