Vulnerability in Linux Kernel Affecting Multipath TCP Implementation
CVE-2026-80587

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80587?

A vulnerability in the Linux kernel's multipath TCP (MPTCP) implementation has been identified that arises from improper handling of mutually exclusive suboptions as per RFC8684. This vulnerability allows certain suboption combinations to be processed incorrectly during TCP communication, which may lead to unexpected behavior and could potentially be exploited if an attacker sends crafted packets. Restrictions have been enforced in the code to prevent the combination of incompatible suboptions, ensuring that only valid options can be utilized together. The patch aims to enhance the robustness of MPTCP by handling erroneous combinations gracefully, reflecting an ongoing effort to maintain security in network protocols.

Affected Version(s)

Linux eda7acddf8080bb2d022a8d4b8b2345eb80c63ec

Linux eda7acddf8080bb2d022a8d4b8b2345eb80c63ec < 099bfcbd0c16ae9b50aba2a1bea033e63f895da7

Linux eda7acddf8080bb2d022a8d4b8b2345eb80c63ec

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.