Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-80652

Published Aug 28, 2026

Overview

CVE-2026-80652 is a known-severity vulnerability. It was published on August 28, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp - Treat zero-length cert chain as query for blob lengths

When handling a PDH export, treat a zero-length userspace cert chain buffer

as a request to query the length of the relevant blobs. Failure to account

for the zero-length buffer trips a BUG_ON() when running with

CONFIG_DEBUG_VIRTUAL=y due to trying to get the physical address of the

ZERO_SIZE_PTR (returned by kzalloc() on the bogus allocation).

kernel BUG at arch/x86/mm/physaddr.c:28 !

Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI

CPU: 30 UID: 0 PID: 28580 Comm: syz.2.18 Kdump: loaded

Tainted: G W 6.18.16-smp-DEV #1 NONE

Tainted: [W]=WARN

Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 12.62.0-0 11/19/2025

RIP: 0010:__phys_addr+0x16a/0x180 arch/x86/mm/physaddr.c:28

RSP: 0018:ffffc9008329fc80 EFLAGS: 00010293

RAX: ffffffff8179110a RBX: 0000778000000010 RCX: ffff8884e6992600

RDX: 00000000000000

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-80652?

CVE-2026-80652 is a known-severity vulnerability. It was published on August 28, 2026.

How severe is CVE-2026-80652?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-80652?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-80652?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-80652 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.