CVE-2026-80640

Source
https://cve.org/CVERecord?id=CVE-2026-80640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80640
Downstream
Published
2026-08-28T06:48:52.650Z
Modified
2026-08-30T03:48:20.872088708Z
Summary
cxl/fwctl: Fix __fortify_panic
Details

In the Linux kernel, the following vulnerability has been resolved:

cxl/fwctl: Fix _fortifypanic

Fix a runtime assertion in cxlctlgetsupported_features(). Fortify complains that it is potentially overflowing the entries array per __countedbyle(numentries). Quiet the false positive by initializing @numentries earlier.

memcpy: detected buffer overflow: 48 byte write of buffer size 0 WARNING: lib/string_helpers.c:1036 at __fortify_report+0x4d/0xa0, CPU#7: fwctl/1398 RIP: 0010:__fortify_report+0x50/0xa0 Call Trace: _fortifypanic+0xd/0xf cxlctlgetsupportedfeatures.cold+0x23/0x35 [cxlcore]

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80640.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4d1c09cef2c244bd19467c016a3e56ba28ecc59d
Fixed
b8d15e85596ad8993d42e0703a9741961a2f03eb
Fixed
18c67ecc5dafe14055edcea53f36f4e31df1816b
Fixed
6c9d2e87df40d606f1c85143e9acb1ecff463d5e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80640.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80640.json"