Linux Kernel Vulnerability in UFS Core Component
CVE-2026-80690

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80690?

A vulnerability in the Linux kernel's UFS core has been identified where the hba->rpmbs list is not properly initialized within the ufshcd_alloc_host() function. This oversight can lead to a NULL pointer dereference during the device teardown process if the ufs_rpmb_probe() function fails. Such a failure poses a risk of system instability and could potentially be exploited in specific scenarios, underscoring the importance of updating to the patched versions.

Affected Version(s)

Linux b06b8c421485e0e96d7fd6aa614fb0b6f2778a03

Linux b06b8c421485e0e96d7fd6aa614fb0b6f2778a03 < 0279fd451a9971c0d5b959fc59f3e11b55e1694e

Linux 6.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.