{"id":"CVE-2026-80990","summary":"net: thunderbolt: Release the Rx HopID that was handed out on mismatch","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: thunderbolt: Release the Rx HopID that was handed out on mismatch\n\ntb_xdomain_alloc_in_hopid() passes the wanted HopID to ida_alloc_range()\nas the lower bound, so a taken id is not an error there: the allocator\nreturns the next free one above it. tbnet_connected_work() asks for the\npeer's transmit path, treats any other id as a failure and returns\nwithout releasing what it got, so that allocation stays live for the rest\nof the XDomain connection with nothing left holding a reference to it.\n\nRelease the id when it is not the one we asked for, the same way the\nerror unwind at the end of the function releases the expected one.","modified":"2026-09-13T03:47:00.854543112Z","published":"2026-09-11T19:42:47.534Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80990.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/2f1463554d0561a2fead81e3888604e5c1125e29"},{"type":"WEB","url":"https://git.kernel.org/stable/c/61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80990.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80990"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"180b0689425c6fb2b35e69a3316ee38371a782df"},{"fixed":"9eac1817bfc5fa76e3a2d1b8fd824cc6ef5a9ab0"},{"fixed":"61ff3c353e5d2ff4eb9d0b6d8d9e47805b136eea"},{"fixed":"1c361f6cf39be7cc0ce37c0b67bd1cdf74b0a0c1"},{"fixed":"2f1463554d0561a2fead81e3888604e5c1125e29"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80990.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.13.0"},{"fixed":"6.12.109"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.50"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.4"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80990.json"}}],"schema_version":"1.9.0"}