SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80677

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel, specifically in the driver core where the function dev_has_sync_state() reads the dev->driver variable without proper locking, potentially leading to a race condition during device unbinding. This could result in undefined behavior or crashes due to dereferencing a stale pointer. Linux system administrators and developers should prioritize this issue to ensure the stability and security of their systems, particularly those managing device drivers.

CVE
CVE-2026-80677
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() dev_has_sync_state() reads dev->driver twice without holding device_lock() -- once for the NULL check and once to dereference ->sync_state. Some callers only hold device_links_write_lock, which doesn't prevent a concurrent unbind from clearing dev->driver via device_unbind_cleanup(). Fix it by reading dev->driver exactly once with READ_ONCE(), pairing with the WRITE_ONCE() in device_set_driver().