{"id":"CVE-2026-80997","title":"kernel: net: ipa: fix stalled modem TX queue after runtime resume (CVE-2026-80997)","summary":"A flaw was found in the Linux kernel's IP Accelerator (IPA) network driver. Specifically, the `ipa_start_xmit()` function incorrectly manages the transmit (TX) queue during a device's runtime resume process. This can lead to the TX queue s…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-821","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","affected":["enterprise_linux 10"],"published":"2026-09-11","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:01:51+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80997.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80997.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-80997"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532044"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80997"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80997"},{"url":"https://git.kernel.org/pub/scm/linux/security/vulns.git/plain/cve/published/2026/CVE-2026-80997.mbox"},{"url":"https://git.kernel.org/stable/c/30d5226bac52073c91ce85c2dcff93b866baefdb"},{"url":"https://git.kernel.org/stable/c/62da38b4b3a0dd74a3e0eecf4992d40385924205"},{"url":"https://git.kernel.org/stable/c/30cef9c1229a36a9c80edb29296459849a2fbaa3"},{"url":"https://git.kernel.org/stable/c/3cbfd627ee720f3d2460d2cbe2fe9e4130240db6"}],"tags":["csaf","vex","red-hat","cve.org","score-dispute"],"epss":0.00603,"epssPercentile":0.47251,"scores":{"vendor":5.5,"cna":7.5},"ingestedAt":"2026-09-14T15:23:07.476Z","slug":"CVE-2026-80997","body":"## Overview\n\nA flaw was found in the Linux kernel's IP Accelerator (IPA) network driver. Specifically, the `ipa_start_xmit()` function incorrectly manages the transmit (TX) queue during a device's runtime resume process. This can lead to the TX queue stopping permanently because the mechanism intended to restart it is consumed prematurely. Consequently, the cellular data path can become unresponsive, resulting in a Denial of Service (DoS) for network communication.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 10 · no fix planned: Red Hat Enterprise Linux 10 · updated 2026-09-14 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-80997.json)\n\n**kernel: net: ipa: fix stalled modem TX queue after runtime resume** — rated Low by Red Hat. Released 2026-09-11, updated 2026-09-14.\n\nAffected:\n\n- Red Hat Enterprise Linux 10\n\nNo fix planned:\n\n- Red Hat Enterprise Linux 10\n\nNot affected:\n\n- Red Hat Enterprise Linux 6\n- Red Hat Enterprise Linux 7\n- Red Hat Enterprise Linux 8\n- Red Hat Enterprise Linux 9\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":202730,"id":"CVE-2026-80997","ts":1789403715326,"field":"cvss","old":"7.5","new":"5.5"},{"seq":202729,"id":"CVE-2026-80997","ts":1789403715326,"field":"severity","old":"high","new":"medium"},{"seq":183604,"id":"CVE-2026-80997","ts":1789356676069,"field":"cvss","old":"7.5","new":"4.7"},{"seq":183603,"id":"CVE-2026-80997","ts":1789356676069,"field":"severity","old":"high","new":"medium"},{"seq":153186,"id":"CVE-2026-80997","ts":1789285349460,"field":"cvss","old":null,"new":"7.5"},{"seq":153185,"id":"CVE-2026-80997","ts":1789285349460,"field":"severity","old":"none","new":"high"},{"seq":109572,"id":"CVE-2026-80997","ts":1789183732463,"field":"cvss","old":null,"new":"4.7"},{"seq":109571,"id":"CVE-2026-80997","ts":1789183732463,"field":"severity","old":"none","new":"medium"}]}