Use-After-Free Vulnerability in Linux Kernel TCP-AO Implementation
CVE-2026-80850

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80850?

A vulnerability in the TCP-AO implementation of the Linux kernel could lead to use-after-free scenarios. When TCP-AO is configured, the validation of keys associated with connected sockets does not properly manage the socket's attachment to the Virtual Routing and Forwarding (VRF) domain. This oversight allows a condition where, during a connection's establishment and VRF detachment race, an old pointer can be accessed after it has been freed. As a result, this can lead to instability and potential exploitation within the network stack, especially under high-load scenarios. The issue has been corrected to ensure consistent handling of socket memory after the validation process, preventing access to freed objects.

Affected Version(s)

Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 594ba77210a1f065832211851a2d7e14d11fcbdb

Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 70051a57786d5b23f059fbaf5c8241eca14d42ed

Linux 248411b8cb8974a1e1c8e43123c1e682fbd64969 < 284d7fd0eec8774bd6214921fbf525cf907c590e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.