---
id: CVE-2026-80851
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  gtp: serialize PDP context updates

  PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
  network device is being unregistered
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  gtp: serialize PDP context updates

  PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
  network device is being unregistered. The latter is serialized b…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    5f77ddb2756340c1b05381674ca025d52998005e
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    3d950e98f74af9611925a5226edced02155f6ed1
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    6df4f05bc2991467939d7d80b6f7e121559cc3df
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    1e995498d29784a06a2b2899370a1926cfc8410d
  - >-
    Linux >= 459aa660eb1d8ce67080da1983bb81d716aa5a69 <
    498386b6d402737db1e2eeed4c385acbf0ef9e34
  - Linux 4.7
published: '2026-09-04'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T11:17:40.540'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80851'
references:
  - url: 'https://git.kernel.org/stable/c/1e995498d29784a06a2b2899370a1926cfc8410d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3d950e98f74af9611925a5226edced02155f6ed1'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/498386b6d402737db1e2eeed4c385acbf0ef9e34'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5f77ddb2756340c1b05381674ca025d52998005e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6df4f05bc2991467939d7d80b6f7e121559cc3df'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b4ac2a5ce5a96ec21ed48f60d30b52b1fb22c62a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.09961
ingestedAt: '2026-10-03T11:43:42.122Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

gtp: serialize PDP context updates

PDP contexts can be deleted through GTP_CMD_DELPDP or while the GTP
network device is being unregistered. The latter is serialized by RTNL,
but the generic-netlink delete path only holds RCU.

Running both paths concurrently can therefore make both paths delete the
same PDP context. The issue was found through static analysis and
reproduced on a KASAN-enabled kernel by a simple two-thread program
racing GTP_CMD_DELPDP against RTM_DELLINK:

  Oops: general protection fault, probably for non-canonical address
  KASAN: maybe wild-memory-access in range
         [0xdead000000000120-0xdead000000000127]
  RIP: gtp_genl_del_pdp+0x1c1/0x420 [gtp]
  RBP: dead000000000122

The second deletion dereferenced the poisoned hlist pprev pointer.

Serialize gtp_pdp_add(), gtp_genl_del_pdp(), and gtp_dellink() with a
shared mutex. Keep the mutex held until the final use of a PDP context in
the NEWPDP path, and keep the RCU read-side section around the complete
PDP context use in the DELPDP path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
