Missing initialization of resource in Linux kernel - CVE-2026-80586
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information, corrupt data, or cause a denial of service.
The vulnerability exists due to improper state reset in MPTCP DSS option parsing in net/mptcp/options.c when processing malformed DSS options with an unexpected size. A remote attacker can send crafted MPTCP packets to disclose sensitive information, corrupt data, or cause a denial of service.
The issue can occur when a malformed DSS option is followed by another DSS option or MPC plus data, causing inconsistent state or access to uninitialized data.
Affected software
How to mitigate CVE-2026-80586
External References
- https://git.kernel.org/stable/c/15e35fdad7a5576bf3f1c8d688877aeb5d1b506b
- https://git.kernel.org/stable/c/192878df582c51d440bf7b91a15f297f29f2b596
- https://git.kernel.org/stable/c/1fade1b2ac5b1a4948e538fae7313bea57b5ac36
- https://git.kernel.org/stable/c/26dac5c9ffb20812b475fdf253eb04fab99cff3b
- https://git.kernel.org/stable/c/27ed642a4e7e4b5df4b8522c72c457a67e052493
- https://git.kernel.org/stable/c/35772b4981f38ba8059372cde8753e8e477e98ec
- https://git.kernel.org/stable/c/4e80eff5c1c893aca2ac1d202f0b256d2e52ecde
- https://git.kernel.org/stable/c/b1256090816ec46011601e084be580731df58fc7