TCP State Lookup Vulnerability in Linux Kernel
CVE-2026-80875

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80875?

A vulnerability in the Linux kernel's TCP state handling may lead to incorrect interpretation of network packets containing IPv6 extension headers. The issue arises as the kernel struggles to accurately retrieve the TCP header due to a mishandling of transport offsets during state lookup. When an IPv6 packet with extension headers is processed, it can result in the kernel examining incorrect bytes, potentially impacting the flow of network traffic. Proper parsing of transport offsets is crucial for maintaining the integrity of TCP state management.

Affected Version(s)

Linux 0bbdd42b7efa66685b6d74701bcde3a596a3a59d < 2d06e0897ce18228d199887f0823b431d841dd03

Linux 0bbdd42b7efa66685b6d74701bcde3a596a3a59d < 816efb7fc0aeae986e63ac73b428dd97a4ef69f5

Linux 0bbdd42b7efa66685b6d74701bcde3a596a3a59d < 5848e914b85e360a2dd9d19c00a72e2ea9617dd0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.