From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D1E6A442FB2 for ; Wed, 26 Aug 2026 14:41:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787755296; cv=none; b=Fg2knvUq9mGsrPU2/dK0phqhNdplqIcTJlnwOUdOz1PXmCmNOVzgWpEfL4OudB70iogDamxtxpITbrcnwYnrghYGw4OCPaaI9qfxkAaFt9zGniObmwQclyut6AJs7R7n9Q1pj7yzALOd4gDUWmFt3/JNyqTmQGfMAn3X5RwOjtw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787755296; c=relaxed/simple; bh=ncZhEhgfcXMos8wL/Nq7Zq2tlpUZPMQTDeobJRD8NUE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=famaag9Mc+LX/wqpNWUX4zENLgyPds7NpjVSYt9b4OqJqqp0cuxs0Qo+zdiCqh8q/e5XN4Mj398Lc0RNN9JqwjSebXRznMJa0rHrpTo3QhJAyhZn5P/+Kc2GgEvLYJvxYXyY/JtByS5rNj+zYSmVUPSdXLsODx791qlBWRUyR64= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=dQ/5h6lV; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="dQ/5h6lV" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 169BA1F000E9; Wed, 26 Aug 2026 14:41:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1787755294; bh=6DkBZOozkRlnioBH0ED2xm/S2yHPP4yhhcFZd4zu4/s=; h=From:To:Cc:Subject:Date:Reply-To; b=dQ/5h6lV6yzO2YOd3ZRzwhX38g0GdAqqh5MXDJ1XsUYOGM0JlJcBvC6BK8kjEZyAK 8WthwgT5u1c4aez+eu+pRZ8j9JotMbqZaz2l9KzMBHtju1xQ5g32bLZc4BoGgZprNI zzVj0QV9BBc/sYnbsbxKI2NxkGy29Z+K1cmuGeT0= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80586: mptcp: options: reset DSS fields in case of unexpected size Date: Wed, 26 Aug 2026 16:38:22 +0200 Message-ID: <2026082616-CVE-2026-80586-008c@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3469; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=AvxvujBqgDQAhOVPBafWjFfSMJ5zyQVb9AlbE62g26c=; b=owGbwMvMwCRo6H6F97bub03G02pJDFl9v2R2lloYPQ5QmPk4fcGL9lDj+7k7mefkR796eTJtn pPrsS2vOmJZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAilQ8Y5ukfjVgncMv2i9Fl f9bTOqnXAjfI3WeYXxg05YHNZ5P7F6zPXfC089veGsbMDAA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpected size A remote peer could send a malformed DSS with a wrong size, followed by another DSS or MPC + Data. In this case, the first suboption will be ignored, but leaving some fields written, which could lead to inconsistency or access uninitialized data. Explicitly reset the fields that could have been modified in case of unexpected size. The Linux kernel CVE team has assigned CVE-2026-80586 to this issue. Affected and fixed versions =========================== Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 5.10.266 with commit 15e35fdad7a5576bf3f1c8d688877aeb5d1b506b Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 5.15.217 with commit b1256090816ec46011601e084be580731df58fc7 Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 6.1.184 with commit 192878df582c51d440bf7b91a15f297f29f2b596 Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 6.6.153 with commit 26dac5c9ffb20812b475fdf253eb04fab99cff3b Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 6.12.105 with commit 4e80eff5c1c893aca2ac1d202f0b256d2e52ecde Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 6.18.46 with commit 1fade1b2ac5b1a4948e538fae7313bea57b5ac36 Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 7.1.10 with commit 27ed642a4e7e4b5df4b8522c72c457a67e052493 Issue introduced in 5.6 with commit 648ef4b88673dadb8463bf0d4b10fbf33d55def8 and fixed in 7.2 with commit 35772b4981f38ba8059372cde8753e8e477e98ec Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80586 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/mptcp/options.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/15e35fdad7a5576bf3f1c8d688877aeb5d1b506b https://git.kernel.org/stable/c/b1256090816ec46011601e084be580731df58fc7 https://git.kernel.org/stable/c/192878df582c51d440bf7b91a15f297f29f2b596 https://git.kernel.org/stable/c/26dac5c9ffb20812b475fdf253eb04fab99cff3b https://git.kernel.org/stable/c/4e80eff5c1c893aca2ac1d202f0b256d2e52ecde https://git.kernel.org/stable/c/1fade1b2ac5b1a4948e538fae7313bea57b5ac36 https://git.kernel.org/stable/c/27ed642a4e7e4b5df4b8522c72c457a67e052493 https://git.kernel.org/stable/c/35772b4981f38ba8059372cde8753e8e477e98ec