Linux Kernel Vulnerability Affecting MLX5 Driver
CVE-2026-80880

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80880?

A vulnerability in the Linux kernel's MLX5 driver related to implicit On-Demand Paging (ODP) has been identified where modifications to parent memory keys (mkeys) are not effectively processed in place. Any request for a change necessitates a complete reconstruction of the parent mkey due to the configuration of its child mkeys. The absence of user-specified translations forces the implicit values to be utilized, which then triggers the mlx5_ib_reg_user_mr() function. This design flaw introduces potential racing conditions related to access permissions on mkeys, highlighting a critical area for performance and security optimizations within the driver.

Affected Version(s)

Linux ef3642c4f54d3493c92c71faf46139b2473bc532

Linux ef3642c4f54d3493c92c71faf46139b2473bc532

Linux ef3642c4f54d3493c92c71faf46139b2473bc532 < 94f7e50eb6b2ce7fbd9aeac1db22460d2013a3fb

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.