Incorrect calculation in Linux kernel - CVE-2026-90054
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt TCP stream data.
The vulnerability exists due to incorrect calculation of the retransmission length in the TCP retransmission path when retransmitting TCP urgent data across multiple segments. A remote attacker can send TCP urgent data that is retransmitted across multiple segments to corrupt TCP stream data.
Affected software
How to mitigate CVE-2026-90054
External References
- https://git.kernel.org/stable/c/3d4e005c198dc410ad568f832bffa7569c059ff8
- https://git.kernel.org/stable/c/47eb90299e6882d6445672530dd7c51ac33ebdbd
- https://git.kernel.org/stable/c/4fd2ee4ac154c204d95d8db72221446dac5af9b8
- https://git.kernel.org/stable/c/711bfd762bec05fb19bc3b17cbb157c39f4e66da
- https://git.kernel.org/stable/c/8eb51013b6308870479a64b4a2a018697b997849
- https://git.kernel.org/stable/c/b8f08a94b2a4addc39249dcf9c792e786108621b
- https://git.kernel.org/stable/c/ce2b807f42ed5e55567b8864ab72963f90779270
- https://git.kernel.org/stable/c/ebe55406404f3cb28e36d2b668e2c6c05026ec29