CVE-2026-80667

high

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: LAG, MPESW, Fix missing complete() on devcom error mlx5_mpesw_work() returned without calling complete() when mlx5_lag_get_devcom_comp() returned NULL. A caller that queued the work and waited on mpesww->comp would block indefinitely. Funnel the early-return path through a new "complete" label so the waiter is always woken.

References

https://git.kernel.org/stable/c/d4b85f9a668b9c44216bb78daf4ec1a915cc92d1

https://git.kernel.org/stable/c/6a802de97a8bf8d5f1e4a048c67de9a8c2d2f9eb

https://git.kernel.org/stable/c/68cdbe498da8475cfd49591954e3db8fc6582eda

https://git.kernel.org/stable/c/4d720c6c60e1852253b68aeee3044ebed5243adb

Details

Source: Mitre, NVD

Published: 2026-08-28

Updated: 2026-08-28

Risk Information

CVSS v2

Base Score: 6.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00168