CVE-2026-80588 PUBLISHED

mptcp: reclaim forward-allocated memory on RX path errors

Assigner: Linux
Reserved: 26.08.2026 Published: 26.08.2026 Updated: 26.08.2026

In the Linux kernel, the following vulnerability has been resolved:

mptcp: reclaim forward-allocated memory on RX path errors

After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"), errors in the receive path prior to queueing skbs into the receive queue do not trigger forward-allocated memory reclaiming.

Prevent forward memory from growing unboundedly in pathological drop scenarios by explicitly reclaiming memory when skbs are dropped.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from a84164847b1e0a106ebc46821e5d2f9b775c9dc8 to 473f1a5ab2abc98dd9e74b95b9c23c66c47535cc (excl.)
  • affected from 9db5b3cec4ec1c0cd3239689f5c8653d691a1754 to 8277f48a06d3aa1441f6d0b6998ccc0360d30ed8 (excl.)
  • affected from 9db5b3cec4ec1c0cd3239689f5c8653d691a1754 to 41b49a8b914ec7dcb03eae93fb27f3c464078644 (excl.)
  • affected from 6.18.35 to 6.18.46 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.19 is affected
  • unaffected from 0 to 6.19 (excl.)
  • unaffected from 6.18.46 to 6.18.* (incl.)
  • unaffected from 7.1.10 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References