Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80694— net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: net: ethernet: mtk_eth_soc:在 poll_controller 中向 mtk_handle_irq_rx 传递 eth 参数 mtk_handle_irq_rx 期望接收一个 struct mtk_eth 指针(与 request_irq 的 cookie 相匹配),但 mtk_poll_controller 错误地传递了 net_device 。如果启用了 CONFIG_NET_POLL_CONTROLLER,调用 ndo_poll_contro

CVSS 9.8 · Critical EPSS 0.17% · P6

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux 8186f6e382d8719d0a4bc0ef218c4dd7cf55b496< 3bd58ac9ca0c552651f533c1bd280dd19ae7d4e8 affected
8186f6e382d8719d0a4bc0ef218c4dd7cf55b496< 276f1f180f55d56cf5992a581e20ed2b3dfa6ced affected
8186f6e382d8719d0a4bc0ef218c4dd7cf55b496< 7eb46318d53940dab63dea7130e720b67a656104 affected
8186f6e382d8719d0a4bc0ef218c4dd7cf55b496< e095f249e2209674f6366f6db0383a2b96e19239 affected
4.8 affected
< 4.8 unaffected
6.12.103≤ 6.12.* unaffected
6.18.44≤ 6.18.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80694

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_irq_rx in poll_controller mtk_handle_irq_rx expects a struct mtk_eth * (matching the request_irq cookie), but mtk_poll_controller incorrectly passed the net_device *. Calling ndo_poll_controller with CONFIG_NET_POLL_CONTROLLER enabled would then crash.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 8186f6e382d8719d0a4bc0ef218c4dd7cf55b496 ~ 3bd58ac9ca0c552651f533c1bd280dd19ae7d4e8 -
Linux Linux 4.8 -

II. Public POCs for CVE-2026-80694

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80694

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80694 (4)

Same Patch Batch · Linux · 2026-08-28 · 135 CVEs total

CVE-2026-80668 9.8 CRITICAL netfilter: nf_conntrack_expect: use conntrack GC to reap expectations
CVE-2026-80600 9.8 CRITICAL batman-adv: dat: acquire ARP hw source only after skb realloc
CVE-2026-80634 9.8 CRITICAL netfilter: flowtable: avoid num_encaps underflow on bridge VLAN untag
CVE-2026-80673 9.8 CRITICAL ntfs: bound the look-ahead attribute-list entry in ntfs_external_attr_find()
CVE-2026-80630 9.8 CRITICAL net/sched: sch_fq_codel: Do not call qdisc_tree_reduce_backlog during peek before restorin
CVE-2026-80681 9.8 CRITICAL vxlan: re-fetch eth header after route_shortcircuit()
CVE-2026-80674 9.8 CRITICAL ntfs: validate resident attribute lists and harden the validator
CVE-2026-80609 9.8 CRITICAL qede: fix out-of-bounds check for cqe->len_list[]
CVE-2026-80714 9.8 CRITICAL ipvs: do not propagate one-packet flag to synced conns
CVE-2026-80612 9.8 CRITICAL net: lwtunnel: Drop skb metadata before LWT encapsulation
CVE-2026-80617 9.8 CRITICAL net: airoha: fix foe_check_time allocation size
CVE-2026-80693 9.3 CRITICAL idpf: bound interrupt-vector register fill to the allocated array
CVE-2026-80671 9.3 CRITICAL perf sched: Fix register_pid() overflow, strcpy, and BUG_ON
CVE-2026-80684 9.3 CRITICAL KVM: s390: pci: Fix NULL dereference on AIBV allocation failure
CVE-2026-80670 9.1 CRITICAL perf tools: Use perf_env__get_cpu_topology() in machine__resolve()
CVE-2026-80603 9.1 CRITICAL netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read
CVE-2026-80672 8.8 HIGH ntfs: fix u16 truncation of restart-area length check
CVE-2026-80633 8.8 HIGH iommufd: Take dma_resv lock before dma_buf_unpin() in release path
CVE-2026-80692 8.8 HIGH Bluetooth: hci_sync: hold conn in hci_connect_acl/le_sync() callbacks
CVE-2026-80683 8.8 HIGH Bluetooth: SCO: give the socket its own sco_conn reference

Showing top 20 of 135 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80694

No comments yet


Leave a comment