SB2026082749 - Improper input validation in Linux kernel mptcp



SB2026082749 - Improper input validation in Linux kernel mptcp

Published: August 27, 2026

Security Bulletin ID SB2026082749
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-80587)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the MPTCP option parser when processing incoming MPTCP suboptions. A remote attacker can send specially crafted packets with inconsistent suboption combinations to execute arbitrary code.

The issue affects handling of mutually exclusive or unexpected combinations of MPTCP suboptions.


Remediation

Install update from vendor's website.