---
cve: "CVE-2026-80585"
severity: "CRITICAL"
cvss: 9.4
epss: "0.3%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-08-26 15:17:14"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-20T02:15:46+02:00"
---

# CVE-2026-80585

> 9.4 CRITICAL

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

mptcp: fastopen: only mark MPTFO subflows with SYN data

Passive TCP Fast Open accepts a valid-cookie SYN even when it carries
no data. In that case the child socket's receive queue is intentionally
left empty.

mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking
for queued SYN data. That made data-less TFO SYNs hit a WARN and, if
the warning was non-fatal, left stale MPTFO state behind. The stale
flag could later trigger a state-confusion bug in
check_fully_established().

Only mark the subflow as MPTFO after confirming that an SKB was queued.
Return quietly when the receive queue is empty.

Note that mptcp_subflow_context's is_mptfo field is now not just about
subflows where the TFO was present, but about MPTFO subflow that
consumed SYN data. Only having a valid cookie but not carrying data is
not really "doing TFO".

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- Kernel ≥ 6.6.153
- Kernel ≥ 6.12.105
- Kernel ≥ 6.18.46
- Kernel ≥ 7.1.10

## Referenzen

- <https://git.kernel.org/stable/c/f75f174edc865738522e514d042cf5627f084859>
- <https://git.kernel.org/stable/c/fca7e444c04689fe4cc6b56f2725f804a4bb1ef9>
- <https://git.kernel.org/stable/c/75e564b2ced1cc3d9a8904c7d2d2bb448fffb8b5>
- <https://git.kernel.org/stable/c/72b4a0c51a4b550d40301d60a366b429b8c8e78d>
- <https://git.kernel.org/stable/c/e00b63056fb4f261455b3e5df5268a1f8ce47a87>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-80585) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
