CVE-2026-80669

Source
https://cve.org/CVERecord?id=CVE-2026-80669
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80669.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80669
Downstream
Published
2026-08-28T06:49:10.511Z
Modified
2026-08-30T03:48:20.957962780Z
Summary
bpf: Disable xfrm_decode_session hook attachment
Details

In the Linux kernel, the following vulnerability has been resolved:

bpf: Disable xfrmdecodesession hook attachment

BPF LSM programs can currently attach to xfrmdecodesession(). That hook may return an error, but securityskbclassifyflow() calls it from a void path and triggers BUGON() if an error is returned.

Disable BPF attachment to the hook to prevent a BPF LSM program from turning packet classification into a full panic.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80669.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
9e4e01dfd3254c7f04f24b7c6b29596bc12332f3
Fixed
aa265d47308775c5501073b08133623bcb5421f9
Fixed
6b44c6660aa1c9b843e450a623ac4a8484919dce
Fixed
4ae780d173ef40d4f7cb76935dc2d55fbf380009
Fixed
49fa1be621dde8f526d36e5791aded8fafda1e9c
Fixed
1bb3b6a5c3c5cc814eae4ff0212fdced36f8bce9
Fixed
12091470c6b4c1c14b2de12dcbae2ada6cb6d20b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80669.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80669.json"