SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80736

HIGH · CVSS 7.8 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's Thunderbolt implementation, specifically in the handling of bandwidth group reservations. An improper indexing issue allows access to an out-of-bounds array element, potentially leading to miscalculated bandwidth allocations. Linux system administrators and developers utilizing Thunderbolt technology should prioritize addressing this vulnerability to ensure proper bandwidth management and system stability.

CVE
CVE-2026-80736
Severity
HIGH
CVSS
7.8
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Fix bandwidth group reservation indexing Valid bandwidth group IDs range from 1 through MAX_GROUPS, while Group ID 0 is reserved. tb_consumed_dp_bandwidth() uses the Group ID directly to index its local group_reserved[] array. The array currently has MAX_GROUPS entries, so its valid indices are 0 through MAX_GROUPS - 1. Group ID MAX_GROUPS therefore accesses one element past the end, and the final group's reserved bandwidth is not included when the array is summed. Give group_reserved[] MAX_GROUPS + 1 entries so direct Group ID indexing covers the reserved ID 0 and valid IDs 1 through MAX_GROUPS.