SB2026082749 - Improper input validation in Linux kernel mptcp
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-80587)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in the MPTCP option parser when processing incoming MPTCP suboptions. A remote attacker can send specially crafted packets with inconsistent suboption combinations to execute arbitrary code.
The issue affects handling of mutually exclusive or unexpected combinations of MPTCP suboptions.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/099bfcbd0c16ae9b50aba2a1bea033e63f895da7
- https://git.kernel.org/stable/c/6bab907292155513af397a12ccb488acbfc30d79
- https://git.kernel.org/stable/c/a04dcc784959e4702048785d87e0d029bd2fbdcb
- https://git.kernel.org/stable/c/b6ee361524641f57b2e2363f7737f20e17f67827
- https://git.kernel.org/stable/c/dc1d8d3eb345c616fbe922a010fa391c72c54d52