Improper input validation in Linux kernel - CVE-2026-80738
Published: September 4, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper validation of socket types in the bpf_tcp_gen_syncookie and bpf_tcp_check_syncookie helpers when processing a socket pointer that represents a mini-socket. A local user can invoke the helpers with a mini-socket pointer to cause a denial of service.