0.0
NA
CVE-2026-80645
rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc()
Description

In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() With a list_for_each() loop, if we don't find the item we are looking for in the list, then the loop exits with the iterator, which is "dbell" in this loop, pointing to invalid memory. This code uses the "found" variable to determine if we have found the doorbell we are looking for or not. However, the problem that the "found" variable needs to be set to false at the start of each iteration, otherwise after the first correct doorbell, then everything is marked as found. Reset the "found" to false at the start of the iteration and move the variable inside the loop.

INFO

Published Date :

Aug. 28, 2026, 8:16 a.m.

Last Modified :

Aug. 28, 2026, 8:16 a.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-80645 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Fix Linux kernel rapidio/tsi721 driver to prevent invalid memory access.
  • Apply the kernel patch for rapidio/tsi721.
  • Ensure the 'found' variable is reset in the loop.
  • Move the 'found' variable declaration inside the loop.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-80645 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-80645 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-80645 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-80645 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 28, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: rapidio/tsi721: prevent a bad dereference in tsi721_db_dpc() With a list_for_each() loop, if we don't find the item we are looking for in the list, then the loop exits with the iterator, which is "dbell" in this loop, pointing to invalid memory. This code uses the "found" variable to determine if we have found the doorbell we are looking for or not. However, the problem that the "found" variable needs to be set to false at the start of each iteration, otherwise after the first correct doorbell, then everything is marked as found. Reset the "found" to false at the start of the iteration and move the variable inside the loop.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/80xxx/CVE-2026-80645.json">CVE-2026-80645</a>
    Added Reference https://git.kernel.org/stable/c/070f356ea4f419e4e85e4089381f4477f41d969e
    Added Reference https://git.kernel.org/stable/c/13092966ba5d8fb214a4efeddc87f9ed0fd2f945
    Added Reference https://git.kernel.org/stable/c/3b5c66e922aa6a3331915a14520848a5b3beccc7
    Added Reference https://git.kernel.org/stable/c/81c06ef66c3ab6eeaa72eb790c90ae043cdb3d43
    Added Reference https://git.kernel.org/stable/c/9e775c3199903d7c09a52530042b1198eab705bd
    Added Reference https://git.kernel.org/stable/c/acd54f42abbbd806464468838dbc04efd203d2be
    Added Reference https://git.kernel.org/stable/c/dc28a14f3e4546b2b06098d24177942540581a5f
    Added Reference https://git.kernel.org/stable/c/fc15e3a30ddd950f009c76765331783b9af94a87
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.