SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-80676

UNKNOWN · CVSS N/A EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of driver attachment, specifically in the hv:vmbus driver, where the match() callback is executed without proper device locking. This oversight can lead to a use-after-free (UAF) condition, potentially allowing an attacker to exploit the system. Organizations running Linux environments, particularly those utilizing the hv:vmbus driver, should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-80676
Severity
UNKNOWN
CVSS
N/A
EPSS
0.17%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Drivers: hv: vmbus: use generic driver_override infrastructure When a driver is probed through __driver_attach(), the bus' match() callback is called without the device lock held, thus accessing the driver_override field without a lock, which can cause a UAF. Fix this by using the driver-core driver_override infrastructure taking care of proper locking internally. Note that calling match() from __driver_attach() without the device lock held is intentional. [1]