TCP Vulnerability in Linux Kernel Affecting Network Performance
CVE-2026-80847
What is CVE-2026-80847?
A vulnerability in the Linux Kernel's TCP implementation could allow an attacker to manipulate the maximum segment size (MSS) to undesirably low values. This flaw arises when the TCP stack processes route-derived ADV_MSS values that deviate from expected norms, potentially causing the effective MSS to drop to zero. By introducing a helper function that clamps the advertised maximum segment size to a minimum threshold, this issue can be mitigated, ensuring stable and reliable network communications.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6b8c20bf61924dfc38fefb145c9f7406d73fae53
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 31cf2349361902769dc323e4dbf4b449795ec288
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1