{"id":"CVE-2026-80851","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered. The latter is serialized b…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a","Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < 5f77ddb2756340c1b05381674ca025d52998005e","Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < 3d950e98f74af9611925a5226edced02155f6ed1","Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < 6df4f05bc2991467939d7d80b6f7e121559cc3df","Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < 1e995498d29784a06a2b2899370a1926cfc8410d","Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 < 498386b6d402737db1e2eeed4c385acbf0ef9e34","Linux 4.7"],"published":"2026-09-04","updated":"2026-10-03","sourceUpdated":"2026-10-03T11:17:40.540","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80851","references":[{"url":"https://git.kernel.org/stable/c/1e995498d29784a06a2b2899370a1926cfc8410d","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3d950e98f74af9611925a5226edced02155f6ed1","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/498386b6d402737db1e2eeed4c385acbf0ef9e34","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5f77ddb2756340c1b05381674ca025d52998005e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/6df4f05bc2991467939d7d80b6f7e121559cc3df","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00209,"epssPercentile":0.09961,"ingestedAt":"2026-10-03T11:43:42.122Z","slug":"CVE-2026-80851","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ngtp: serialize PDP context updates\n\nPDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP\nnetwork device is being unregistered. The latter is serialized by RTNL,\nbut the generic-netlink delete path only holds RCU.\n\nRunning both paths concurrently can therefore make both paths delete the\nsame PDP context. The issue was found through static analysis and\nreproduced on a KASAN-enabled kernel by a simple two-thread program\nracing GTP_CMD_DELPDP against RTM_DELLINK:\n\n  Oops: general protection fault, probably for non-canonical address\n  KASAN: maybe wild-memory-access in range\n         [0xdead000000000120-0xdead000000000127]\n  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]\n  RBP: dead000000000122\n\nThe second deletion dereferenced the poisoned hlist pprev pointer.\n\nSerialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a\nshared mutex. Keep the mutex held until the final use of a PDP context in\nthe NEWPDP path, and keep the RCU read-side section around the complete\nPDP context use in the DELPDP path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}