Memory Initialization Vulnerability in Linux Kernel Affecting J1939 Transport
CVE-2026-80707

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80707?

A vulnerability has been identified in the Linux kernel's J1939 transport subsystem related to improper initialization of receive buffers in the j1939_session_fresh_new() function. Specifically, the allocated buffers were not zeroed, which could lead to residual data exposure. Although this flaw has minimal performance impact in most scenarios—given that the maximum buffer size typically hovers around 65K—proper initialization of buffers is essential for maintaining system integrity and security.

Affected Version(s)

Linux 9d71dd0c70099914fcd063135da3c580865e924c < 348818277a3646d5b9fa60c9d20c00dc4bc86832

Linux 9d71dd0c70099914fcd063135da3c580865e924c

Linux 9d71dd0c70099914fcd063135da3c580865e924c

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.