CVE-2026-53183 (GCVE-0-2026-53183)
Vulnerability from cvelistv5
Published
2026-06-25 08:38
Modified
2026-08-05 12:33
Summary
In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field in the TCP header refers to the MPTCP-level rcv_nxt and it's right edge should not move backward. Such constraint is enforced at DSS option generation time. At the same time, the TCP stack ensures independently that the TCP-level rcv wnd right's edge does not move backward. That in turn causes artificial inflating of the MPTCP rcv window when the incoming data is acked at the TCP level and is OoO in the MPTCP sequence space (or lands in the backlog). As a consequence, the incoming traffic can exceed the receiver rcvbuf size even when the sender is not misbehaving. Prevent such scenario forcibly allowing the TCP subflow to shrink the TCP-level rcv wnd regardless of the current netns setting.
Impacted products
Vendor Product Version
Linux Linux Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Version: f3589be0c420a3137e5902d15705ced6a36f3f43
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "net/mptcp/options.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "bf364b0f10b27679140699821f88af7f01e2a6e3",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            },
            {
              "lessThan": "b1fd13074f22105deec45aa02283e322733e0c2d",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            },
            {
              "lessThan": "aa3861f40ac32706d9e97bfac76984613e278788",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            },
            {
              "lessThan": "653245266913f03fcf21cbca68eed5c197a33e52",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            },
            {
              "lessThan": "c297a4e65c50a2b807d9309b22615080faffa8f3",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            },
            {
              "lessThan": "da23be77e1292cd611e736c3aa17da633d7ddce7",
              "status": "affected",
              "version": "f3589be0c420a3137e5902d15705ced6a36f3f43",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "net/mptcp/options.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "lessThan": "5.19",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.176",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.143",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.94",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.36",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.0.*",
              "status": "unaffected",
              "version": "7.0.13",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.176",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.143",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.94",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.36",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0.13",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1",
                  "versionStartIncluding": "5.19",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: allow subflow rcv wnd to shrink\n\nIn MPTCP connection, the `window` field in the TCP header refers to the\nMPTCP-level rcv_nxt and it\u0027s right edge should not move backward. Such\nconstraint is enforced at DSS option generation time.\n\nAt the same time, the TCP stack ensures independently that the TCP-level\nrcv wnd right\u0027s edge does not move backward. That in turn causes artificial\ninflating of the MPTCP rcv window when the incoming data is acked at the\nTCP level and is OoO in the MPTCP sequence space (or lands in the backlog).\n\nAs a consequence, the incoming traffic can exceed the receiver rcvbuf size\neven when the sender is not misbehaving.\n\nPrevent such scenario forcibly allowing the TCP subflow to shrink the\nTCP-level rcv wnd regardless of the current netns setting."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - The vulnerable code is reachable through received TCP/MPTCP packets on an established MPTCP connection, including an internet-facing MPTCP-enabled service. The attacker can be a remote MPTCP peer sending crafted valid data patterns.\nAC:L - A peer can intentionally send valid MPTCP data that is out of order in MPTCP sequence space, causing TCP-level ACK/window advancement while MPTCP receive space remains consumed. No race or condition outside the attacker\u0027s control is required.\nPR:N - The kernel packet processing path has no privilege or authentication gate once the remote peer establishes an MPTCP connection. Application-level authentication is not required to reach the vulnerable TCP/MPTCP receive and ACK-generation code.\nUI:N - An attacker can target an MPTCP-enabled listener or service directly over the network. No victim user interaction is needed.\nS:U - The impact is within the same kernel/network stack security authority on the affected host. There is no VM escape, sandbox boundary crossing, or separate security scope involved.\nC:N - The bug causes receive-window over-advertisement and excessive receive-buffer consumption, not an out-of-bounds access, use-after-free, or information disclosure primitive. I found no path to reading kernel or application data.\nI:N - The affected logic corrupts flow-control accounting rather than attacker-controlled memory or persistent state. I found no arbitrary write, data modification, or control-flow hijack primitive.\nA:H - A remote peer can drive incoming MPTCP traffic beyond the intended receive-buffer limit, creating kernel socket-buffer memory pressure and denial of service against the host or service. Repeated unauthenticated network triggering makes high availability impact defensible."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:33:50.018Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/bf364b0f10b27679140699821f88af7f01e2a6e3"
        },
        {
          "url": "https://git.kernel.org/stable/c/b1fd13074f22105deec45aa02283e322733e0c2d"
        },
        {
          "url": "https://git.kernel.org/stable/c/aa3861f40ac32706d9e97bfac76984613e278788"
        },
        {
          "url": "https://git.kernel.org/stable/c/653245266913f03fcf21cbca68eed5c197a33e52"
        },
        {
          "url": "https://git.kernel.org/stable/c/c297a4e65c50a2b807d9309b22615080faffa8f3"
        },
        {
          "url": "https://git.kernel.org/stable/c/da23be77e1292cd611e736c3aa17da633d7ddce7"
        }
      ],
      "title": "mptcp: allow subflow rcv wnd to shrink",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-53183",
    "datePublished": "2026-06-25T08:38:57.443Z",
    "dateReserved": "2026-06-09T07:44:35.390Z",
    "dateUpdated": "2026-08-05T12:33:50.018Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…