In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch… (CVE-2026-80990)
A vulnerability in the Linux kernel's Thunderbolt networking code was resolved by ensuring that a resource identifier (Rx HopID) is properly released when it is not the expected one. The issue involved a resource allocation that could remain live without a reference, potentially leading to resource leakage during XDomain connections.
AI Analysis
Technical Summary
The vulnerability in the Linux kernel's Thunderbolt networking subsystem involved improper release of the Rx HopID resource. Specifically, tb_xdomain_alloc_in_hopid() passes a desired HopID to an allocator that returns the next free ID if the requested one is taken. The function tbnet_connected_work() treats any ID other than the peer's transmit path ID as a failure but did not release the allocated ID in that failure case, causing the allocation to remain live without a reference. The fix ensures that the allocated ID is released when it is not the expected one, preventing resource leakage.
Potential Impact
The vulnerability could lead to resource leakage within the Thunderbolt networking code of the Linux kernel during XDomain connections. This may degrade system stability or performance over time due to unreleased resource allocations. There is no indication of direct code execution, privilege escalation, or data exposure from the provided information.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to release the Rx HopID resource properly when it is not the expected one. Users should apply the official Linux kernel updates that include this fix. Since no vendor advisory or patch link is provided, check the Linux kernel mailing lists or official repositories for the patch and update accordingly.
In the Linux kernel, the following vulnerability has been resolved: net: thunderbolt: Release the Rx HopID that was handed out on mismatch… (CVE-2026-80990)
Description
A vulnerability in the Linux kernel's Thunderbolt networking code was resolved by ensuring that a resource identifier (Rx HopID) is properly released when it is not the expected one. The issue involved a resource allocation that could remain live without a reference, potentially leading to resource leakage during XDomain connections.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in the Linux kernel's Thunderbolt networking subsystem involved improper release of the Rx HopID resource. Specifically, tb_xdomain_alloc_in_hopid() passes a desired HopID to an allocator that returns the next free ID if the requested one is taken. The function tbnet_connected_work() treats any ID other than the peer's transmit path ID as a failure but did not release the allocated ID in that failure case, causing the allocation to remain live without a reference. The fix ensures that the allocated ID is released when it is not the expected one, preventing resource leakage.
Potential Impact
The vulnerability could lead to resource leakage within the Thunderbolt networking code of the Linux kernel during XDomain connections. This may degrade system stability or performance over time due to unreleased resource allocations. There is no indication of direct code execution, privilege escalation, or data exposure from the provided information.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to release the Rx HopID resource properly when it is not the expected one. Users should apply the official Linux kernel updates that include this fix. Since no vendor advisory or patch link is provided, check the Linux kernel mailing lists or official repositories for the patch and update accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-33rp-ch35-2jf6
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-80990"]
Threat ID: 6aa4a02b55bf5e2cf5a86b4b
Added to database: 09/12/2026, 00:43:23 UTC
Last enriched: 09/12/2026, 01:22:37 UTC
Last updated: 09/12/2026, 03:01:39 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.