CVE-2026-80586 (GCVE-0-2026-80586)
Vulnerability from cvelistv5
Published
2026-08-26 14:37
Modified
2026-08-27 05:02
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: options: reset DSS fields in case of unexpected size
A remote peer could send a malformed DSS with a wrong size, followed by
another DSS or MPC + Data. In this case, the first suboption will be
ignored, but leaving some fields written, which could lead to
inconsistency or access uninitialized data.
Explicitly reset the fields that could have been modified in case of
unexpected size.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 Version: 648ef4b88673dadb8463bf0d4b10fbf33d55def8 |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"net/mptcp/options.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "15e35fdad7a5576bf3f1c8d688877aeb5d1b506b",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "b1256090816ec46011601e084be580731df58fc7",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "192878df582c51d440bf7b91a15f297f29f2b596",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "26dac5c9ffb20812b475fdf253eb04fab99cff3b",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "4e80eff5c1c893aca2ac1d202f0b256d2e52ecde",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "1fade1b2ac5b1a4948e538fae7313bea57b5ac36",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "27ed642a4e7e4b5df4b8522c72c457a67e052493",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
},
{
"lessThan": "35772b4981f38ba8059372cde8753e8e477e98ec",
"status": "affected",
"version": "648ef4b88673dadb8463bf0d4b10fbf33d55def8",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"net/mptcp/options.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.6"
},
{
"lessThan": "5.6",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.266",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.217",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.184",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.153",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.105",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.46",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.10",
"versionStartIncluding": "5.6",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: options: reset DSS fields in case of unexpected size\n\nA remote peer could send a malformed DSS with a wrong size, followed by\nanother DSS or MPC + Data. In this case, the first suboption will be\nignored, but leaving some fields written, which could lead to\ninconsistency or access uninitialized data.\n\nExplicitly reset the fields that could have been modified in case of\nunexpected size."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - Remote attacker sends crafted TCP segments with malformed MPTCP options that are parsed in the softirq receive path (tcp_v4_rcv/tcp_rcv_established/tcp_data_queue/mptcp_incoming_options/mptcp_get_options), requiring only network reachability to an MPTCP-enabled peer.\nAC:L - Attacker fully controls TCP option bytes on an established MPTCP connection and can deterministically send a size-invalid DSS (setting use_ack/use_map flags) immediately followed by MPC+Data or another DSS in the same header; no race or victim-specific state is required.\nPR:N - Only requires the attacker to be the remote MPTCP/TCP peer of a host with CONFIG_MPTCP enabled; no local account, capabilities, or authenticated access on the victim is needed to reach the vulnerable parser.\nUI:N - Exploitation is fully automated over the network once an MPTCP session exists; the kernel processes malicious segments in softirq without any victim user action beyond ordinary connectivity.\nS:U - Impact is limited to kernel networking/MPTCP connection state on the affected host and does not cross VM, container, or IOMMU security boundaries.\nC:H - Malformed DSS leaves use_ack/use_map/dsn64/data_fin set while data_ack and map fields are never read, so ack_update_msk() and DSS handling consume uninitialized stack values and corrupt metadata that can leak kernel memory contents.\nI:H - Stale DSS flag bits cause forged ack advancement of msk-\u003esnd_una/wnd_end/bytes_acked and bogus DATA_FIN/DSN mapping in skb extensions, corrupting rtx queues and silently altering or truncating application data delivery.\nA:H - Bogus ack state triggers __mptcp_clean_una() WARN_ON_ONCE paths outside recovery, can abort or hang MPTCP connections, and may kernel-panic systems built with panic_on_warn."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T05:02:07.204Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/15e35fdad7a5576bf3f1c8d688877aeb5d1b506b"
},
{
"url": "https://git.kernel.org/stable/c/b1256090816ec46011601e084be580731df58fc7"
},
{
"url": "https://git.kernel.org/stable/c/192878df582c51d440bf7b91a15f297f29f2b596"
},
{
"url": "https://git.kernel.org/stable/c/26dac5c9ffb20812b475fdf253eb04fab99cff3b"
},
{
"url": "https://git.kernel.org/stable/c/4e80eff5c1c893aca2ac1d202f0b256d2e52ecde"
},
{
"url": "https://git.kernel.org/stable/c/1fade1b2ac5b1a4948e538fae7313bea57b5ac36"
},
{
"url": "https://git.kernel.org/stable/c/27ed642a4e7e4b5df4b8522c72c457a67e052493"
},
{
"url": "https://git.kernel.org/stable/c/35772b4981f38ba8059372cde8753e8e477e98ec"
}
],
"title": "mptcp: options: reset DSS fields in case of unexpected size",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-80586",
"datePublished": "2026-08-26T14:37:41.493Z",
"dateReserved": "2026-08-26T14:34:25.769Z",
"dateUpdated": "2026-08-27T05:02:07.204Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…