Improper input validation in Linux kernel - CVE-2026-80587

 

Improper input validation in Linux kernel - CVE-2026-80587

Published: August 27, 2026


Vulnerability identifier: #VU145903
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80587
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in the MPTCP option parser when processing incoming MPTCP suboptions. A remote attacker can send specially crafted packets with inconsistent suboption combinations to execute arbitrary code.

The issue affects handling of mutually exclusive or unexpected combinations of MPTCP suboptions.


Affected software

Linux kernel

How to mitigate CVE-2026-80587

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins