CVE-2026-80885 PUBLISHED

afs: Fix uncancelled rxrpc OOB message handler

Assigner: Linux
Reserved: 26.08.2026 Published: 04.09.2026 Updated: 04.09.2026

In the Linux kernel, the following vulnerability has been resolved:

afs: Fix uncancelled rxrpc OOB message handler

Fix AFS to cancel its OOB message processing (typically to respond to security challenges). Also move OOB message processing to afs_wq so that it's also waited for and make the OOB handler just return if the net namespace is no longer live.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5800b1cf3fd8ccab752a101865be1e76dac33142 to 231414253b648b3518b56f09710b831945d6a2fc (excl.)
  • affected from 5800b1cf3fd8ccab752a101865be1e76dac33142 to d14e96ddd616c8a9fff3b5bab3bf4af0cfc30ec4 (excl.)
  • affected from 5800b1cf3fd8ccab752a101865be1e76dac33142 to a4057e58b07005d0fe0491bdbf1868c1491909ee (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.16 is affected
  • unaffected from 0 to 6.16 (excl.)
  • unaffected from 6.18.40 to 6.18.* (incl.)
  • unaffected from 7.1.5 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References