CVE-2026-80732
Last modified
CVE-2026-80732 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ata: pata_sl82c105: fix bridge revision use-after-free pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b ("PCI: Change all drivers to use pci_device->revision") replaced a configuration-space read with direct access to the cached revision field, but left that access after pci_dev_put(). EPSS estimates a 0.21% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: ata: pata_sl82c105: fix bridge revision use-after-free pci_get_slot() returns a referenced PCI device. Commit 44c10138fd4b ("PCI: Change all drivers to use pci_device->revision") replaced a configuration-space read with direct access to the cached revision field, but left that access after pci_dev_put(). The bridge may therefore be freed before its revision is read. Read the revision before dropping the reference.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < 1268ca9418e2217f2b60705cf4a280b689b26678; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < a626dfca96041842053cf2d1efceb436c4cd8dcf; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < 5ef87b1b4656d675440ceab32a56e69ad958d3a1; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < fa0dca89b4fb0909ffda7b9ab6051af33270f95e; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < dc711fb137b33c12e6ca22b6a9c9b9f21d49e4de; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < a837deeaa37cc3f0e8c4e5c096787047f272c956; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < 56fd78c8c820f527f8003e379ab71004b2e79a44; >= 44c10138fd4bbc4b6d6bff0873c24902f2a9da65, < 7700a31039cdc6715cb6cce7e7a664ee4e945f67 |
| Linux | Linux | 2.6.23 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80732?
How severe is CVE-2026-80732?
How do I fix CVE-2026-80732?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80727In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80728In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80729In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8073The Kirki – Freeform Page Builder, Website Builder & Customi…7.5
- CVE-2026-80730In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80731In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80733In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80734In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2026-80735In the Linux kernel, the following vulnerability has been re…7.3
- CVE-2026-80736In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80737In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80738In the Linux kernel, the following vulnerability has been re…7.3
Are you affected by CVE-2026-80732?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
