TCP Fast Open Vulnerability in Linux Kernel
CVE-2026-80585
Currently unrated
What is CVE-2026-80585?
This vulnerability in the Linux kernel arises from a flaw in the handling of TCP Fast Open (TFO) for MPTCP subflows. Specifically, it allows the acceptance of valid-cookie SYN packets even without accompanying data. This can lead to confusion in the socket state, as it may leave stale Multipath TCP Fast Open (MPTFO) states that can trigger state-validation bugs during the establishment of connections. Proper handling requires the verification of queued SYN data before marking subflows as MPTFO, ensuring accurate state management.
Affected Version(s)
Linux 36b122baf6a8bd46b4a591f12f4ed17b22257408
Linux 36b122baf6a8bd46b4a591f12f4ed17b22257408
Linux 36b122baf6a8bd46b4a591f12f4ed17b22257408 < 75e564b2ced1cc3d9a8904c7d2d2bb448fffb8b5