0.0
NA
CVE-2026-80880
IB/mlx5: Properly support implicit ODP rereg_mr
Description

In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit ODP configuration we cannot change anything in place for the parent mkey. Instead the whole thing needs to be rebuilt if any change is requested. If the user does not specify a translation then force the implicit values which will then fall through the logic into mlx5_ib_reg_user_mr() to allocate a completely new MR. Since implicit children were also touching the mr->pd, this removes another case where the access was racy.

INFO

Published Date :

Sept. 4, 2026, 5:17 p.m.

Last Modified :

Sept. 4, 2026, 5:17 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-80880 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

No affected product recoded yet

Solution
Kernel memory corruption vulnerability fixed by updating the Linux kernel.
  • Update the Linux kernel to the latest version.
  • Apply the provided patch for IB/mlx5.
  • Rebuild the implicit ODP configuration.
  • Ensure all child mkeys are valid.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-80880 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-80880 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-80880 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-80880 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 04, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Properly support implicit ODP rereg_mr Due to all the child mkeys in the implicit ODP configuration we cannot change anything in place for the parent mkey. Instead the whole thing needs to be rebuilt if any change is requested. If the user does not specify a translation then force the implicit values which will then fall through the logic into mlx5_ib_reg_user_mr() to allocate a completely new MR. Since implicit children were also touching the mr->pd, this removes another case where the access was racy.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/80xxx/CVE-2026-80880.json">CVE-2026-80880</a>
    Added Reference https://git.kernel.org/stable/c/5d02b9a2efd11d28d2a8feac7769686b1b871d9c
    Added Reference https://git.kernel.org/stable/c/94f7e50eb6b2ce7fbd9aeac1db22460d2013a3fb
    Added Reference https://git.kernel.org/stable/c/cbc9982c8573fb9e35040063aa78c8ebe768a1ff
    Added Reference https://git.kernel.org/stable/c/d4f84bfa089fe71f775d25beb29303e844494c25
    Added Reference https://git.kernel.org/stable/c/eb7cb798e563b3f3b3baeb9cc6f7455764267e50
    Added Reference https://git.kernel.org/stable/c/ee7a8335069150c3f1893a697ab30bbeca00d796
    Added Reference https://git.kernel.org/stable/c/ee914ef54a7e707453ecb43eb30fb0a5c6dd0d69
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.