
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-80885 is a Linux kernel vulnerability in the AFS (Andrew File System) subsystem involving an uncancelled rxrpc OOB (out-of-band) message handler. The flaw causes AFS to fail to properly cancel its OOB message processing — typically used to respond to security challenges — and to not execute this processing within the appropriate work queue context (afs_wq). It affects Linux kernel version 6.16 through commits prior to the fixes backported into 6.18.40 and 7.1.5, with 7.2 and later being unaffected. The vulnerability was published on September 4, 2026, and is estimated as Medium severity; no official CVSS base score has been assigned at this time (GitHub Advisory, ENISA EUVD).
The root cause is improper resource cleanup (related to CWE-404: Improper Resource Shutdown or Release) in the AFS kernel subsystem's handling of rxrpc OOB messages. When a network namespace is torn down, the OOB message handler is not cancelled and is not bound to the afs_wq work queue, meaning it can continue executing after the namespace is no longer live. This can result in use-after-free conditions, resource leaks, or kernel crashes during namespace teardown. No formal CWE has been assigned, and no public proof-of-concept code is known to exist (GitHub Advisory, Feedly).
A local user with the ability to create network namespaces or trigger AFS operations can cause improper OOB message handler execution, potentially leading to resource leaks, memory corruption, or kernel crashes (denial of service) when network namespaces are torn down. The primary impact is availability (kernel crash/DoS), with a secondary risk of memory corruption that could theoretically affect kernel integrity. There is no evidence of confidentiality impact or remote exploitability (Feedly, GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the publication date. The EPSS score is 0.0, indicating very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and the ability to create network namespaces or trigger AFS operations, significantly limiting the attack surface (Feedly, GitHub Advisory).
Apply the Linux kernel patches that resolve this vulnerability. Fixed commits are available for multiple stable branches: 231414253b64 (one branch), d14e96ddd616 (another branch), and a4057e58b070 (a third branch), corresponding to fixed releases 6.18.40, 7.1.5, and 7.2+. Administrators should update to a patched kernel version as soon as possible. No configuration-based workaround is documented; the recommended action is to apply the upstream kernel fix (GitHub Advisory, Kernel Patch 1, Kernel Patch 2, Kernel Patch 3).
The vulnerability received routine automated coverage from CVE tracking services and aggregators shortly after publication. A Bluesky post from a CVE tracking account noted the disclosure. No notable researcher commentary, vendor statements beyond the kernel fix, or significant media coverage has been identified (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."