CVE-2026-80707
Last modified
CVE-2026-80707 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure it contains no residual data. While there is a potential performance impact if users allocate maximum sized ETP buffers, most real-world use cases are not noticeably affected since the maximum known buffer size is typically around 65K. [mkl: add Message-ID]. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: can: j1939: transport: j1939_session_fresh_new(): initialize receive buffer Zero the allocated buffer in j1939_session_fresh_new() to ensure it contains no residual data. While there is a potential performance impact if users allocate maximum sized ETP buffers, most real-world use cases are not noticeably affected since the maximum known buffer size is typically around 65K. [mkl: add Message-ID]
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9d71dd0c70099914fcd063135da3c580865e924c, < 348818277a3646d5b9fa60c9d20c00dc4bc86832; >= 9d71dd0c70099914fcd063135da3c580865e924c, < f3e120a34b336079479fa10f706f0636eaa6e751; >= 9d71dd0c70099914fcd063135da3c580865e924c, < bbfa49d1e287de44994955b44d19281be3195b44; >= 9d71dd0c70099914fcd063135da3c580865e924c, < 194d67e92197eb820f4c2c6605d9721333b3eba0; >= 9d71dd0c70099914fcd063135da3c580865e924c, < 038bad8e16c2e28acf31f0b527a816fb23a57269; >= 9d71dd0c70099914fcd063135da3c580865e924c, < 8604a3b81b9d0ceaf04fee5f52e701f623a179f9; >= 9d71dd0c70099914fcd063135da3c580865e924c, < d5b3613c7d69d8dcb4dd6704f1f463198ce9f6cf; >= 9d71dd0c70099914fcd063135da3c580865e924c, < eb96c58907922546e415e545fe9a14ea63b02719 |
| Linux | Linux | 5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80707?
How severe is CVE-2026-80707?
How do I fix CVE-2026-80707?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80701In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80702In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80703In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80704In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80705In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80706In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80708In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80709In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-8071The Anti-Spam by CleanTalk. Spam protection WordPress plugin…8.8
- CVE-2026-80710In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80711In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80712In the Linux kernel, the following vulnerability has been re…8.4
Are you affected by CVE-2026-80707?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
