CVE-2026-80730

Source
https://cve.org/CVERecord?id=CVE-2026-80730
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80730.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80730
Downstream
Published
2026-09-03T08:21:48.325Z
Modified
2026-09-05T03:48:34.772282303Z
Summary
ring-buffer: Fix crash passing ERR_PTR to kthread_stop()
Details

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Fix crash passing ERRPTR to kthreadstop()

In testringbuffer()'s outfree cleanup loop, the check !rb_threads[cpu] only catches NULL entries and misses entries that hold an ERR_PTR.

rbthreads[] is static, so unassigned slots are NULL. But when kthreadrunoncpu() fails for a cpu, it stores ERRPTR(-ENOMEM) (or -EINTR) in rbthreads[cpu] before the creation loop jumps to outfree. That entry is non-NULL, so the old !ptr check does not break, and the cleanup proceeds to call kthreadstop() on the ERRPTR. kthreadstop() then dereferences the bogus pointer, crashing the kernel during the late_initcall self-test.

crash logs: BUG: kernel NULL pointer dereference, address: 000000000000001c Oops: 0002 [#1] SMP NOPTI CPU: 1 PID: 1 Comm: swapper/0 Not tainted 7.2.0-rc6-dirty #7 PREEMPT(lazy) RIP: 0010:kthreadstop+0x2e/0x220 RBX: fffffffffffffff4 CR2: 000000000000001c Call Trace: <TASK> testringbuffer+0x1ec/0x650 dooneinitcall+0x6c/0x2c0 kernelinitfreeable+0x21d/0x420 kernelinit+0x15/0x1c0 retfrom_fork+0x21b/0x320 </TASK> Kernel panic - not syncing: Fatal exception

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80730.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
64ed3a049e3e81b801e7c5bb052416152443f585
Fixed
51d78fad30dd9ae45721224103662bdbcf210096
Fixed
93e7044b548a72022208595d2c1b188bb225ce83
Fixed
8532983c312e8b875d7c9e440f8ee4674ea4b711
Fixed
6dd7a06894d6d3dc84319bd0b7d1a7c27df9d902
Fixed
3ea2fd344d93e3cf9503739b09fd702c0d8f8f0b
Fixed
91542863abade2fd4f2b361991f5386ad9d19c8c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80730.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.17.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80730.json"