PT-2026-82969 · Linux · Linux Kernel

CVE-2026-80669

·

Published

2026-08-28

·

Updated

2026-09-03

CVSS v4.0

6.7

Medium

VectorAV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description BPF LSM programs can attach to the xfrm decode session() hook. Because security skb classify flow() calls this hook from a void path, any error returned by the hook triggers a BUG ON() condition, which can lead to a full system panic during packet classification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80669

Affected Products

Linux Kernel