CVE-2026-80588

Summary

In the Linux kernel, the following vulnerability has been resolved:

mptcp: reclaim forward-allocated memory on RX path errors

After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"), errors in the receive path prior to queueing skbs into the receive queue do not trigger forward-allocated memory reclaiming.

Prevent forward memory from growing unboundedly in pathological drop scenarios by explicitly reclaiming memory when skbs are dropped.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxa84164847b1e0a106ebc46821e5d2f9b775c9dc8 < 473f1a5ab2abc98dd9e74b95b9c23c66c47535ccaffected
LinuxLinux9db5b3cec4ec1c0cd3239689f5c8653d691a1754 < 8277f48a06d3aa1441f6d0b6998ccc0360d30ed8affected
LinuxLinux9db5b3cec4ec1c0cd3239689f5c8653d691a1754 < 41b49a8b914ec7dcb03eae93fb27f3c464078644affected
LinuxLinux6.18.35 < 6.18.46affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux6.18.46 <= 6.18.*unaffected
LinuxLinux7.1.10 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References