CVE-2026-80588: mptcp: reclaim forward-allocated memory on RX path errors

Published Aug 26, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mptcp: reclaim forward-allocated memory on RX path errors

After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"), errors in the receive path prior to queueing skbs into the receive queue do not trigger forward-allocated memory reclaiming.

Prevent forward memory from growing unboundedly in pathological drop scenarios by explicitly reclaiming memory when skbs are dropped.

Event History

Aug 26, 2026
CVE Published
via MITRE·02:37 PM
Data Sourced
via MITRE·02:37 PM
Description
Data Sourced
via NVD·03:17 PM
Description

Frequently Asked Questions

1

What conditions trigger the memory growth?

The issue occurs when MPTCP receive-path errors drop socket buffers before they are queued to the receive queue. Pathological drop scenarios can cause forward-allocated memory to grow without bound.

2

Which systems are in scope?

The affected code is in the Linux kernel MPTCP receive path. The regression is associated with the change identified as commit 9db5b3cec4ec, which introduced borrowing forward memory from a subflow.

3

Which fixes are referenced?

The listed stable fixes are commits 473f1a5ab2abc98dd9e74b95b9c23c66c47535cc, 8277f48a06d3aa1441f6d0b6998ccc0360d30ed8, and 41b49a8b914ec7dcb03eae93fb27f3c464078644.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203