CVE-2026-80640. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CISA KEVNot listedBased on the latest collected catalog
EPSS0.2%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview
What is CVE-2026-80640?
In the Linux kernel, the following vulnerability has been resolved:
cxl/fwctl: Fix __fortify_panic
Fix a runtime assertion in cxlctl_get_supported_features(). Fortify complains that it is potentially overflowing the entries array per __counted_by_le(num_entries).
Quiet the false positive by initializing @num_entries earlier.