Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-80587

mptcp: avoid combining some incoming suboptions
Back to all
CVE

CVE-2026-80587

mptcp: avoid combining some incoming suboptions

In the Linux kernel, the following vulnerability has been resolved:

mptcp: avoid combining some incoming suboptions

Some MPTCP suboptions are mutually exclusive according to the RFC8684,

but also because in different places, the code doesn't expect some

combinations to be present. That's specially true for suboptions that

would be present twice, but with different attributes.

The new restrictions are the same as the ones applied on the output

side, with mptcpwriteoptions. The same rules can be reused with a

small fix: an MP_FASTCLOSE can be used with a DSS when the sender picks

this option [1], which is not the case on Linux. Here are the rules:

  Which options can be used together?

  X: mutually exclusive

  O: often used together

  C: can be used together in some cases

  P: could be used together but we prefer not to (optimisations)

  | Opt: | MPC  | MPJ  | DSS  | ADD  |  RM  | PRIO | FAIL |  FC  |

  |------|------|------|------|------|------|------|------|------|

  | MPC  |------|------|------|------|------|------|------|------|

  | MPJ  |  X   |------|------|------|------|------|------|------|

  | DSS  |  X   |  X   |------|------|------|------|------|------|

  | ADD  |  X   |  X   |  P   |------|------|------|------|------|

  | RM   |  C   |  C   |  C   |  P   |------|------|------|------|

  | PRIO |  X   |  C   |  C   |  C   |  C   |------|------|------|

  | FAIL |  X   |  X   |  C   |  X   |  X   |  X   |------|------|

  | FC   |  X   |  X   |  P   |  X   |  X   |  X   |  X   |------|

  | RST  |  X   |  X   |  X   |  X   |  X   |  X   |  O   |  O   |

  |------|------|------|------|------|------|------|------|------|

The only difference is with the 'P': another stack could send and

ADDADDR with other suboptions (DSS, RMADDR), and this should be

allowed.

A few points of attention:

  • In theory, an MPCAPABLE could be used with a RMADDR, but there is

   no reason to add it with a SYN. Note that even with a 4th ACK, it

   doesn't seem to be useful, except when IDs are known in advance via

   another channel. Better not to break that.

  • Now, combining both an MPCAPABLE and an MPJOIN will no longer

   result to a reject of the two options, but only the second suboption

   is ignored. That seems OK to do that for this unexpected error. At

   least now all inconsistent combinations are handled the same way.

   This could change later in next. This also means the explicit checks

   for having both MPC + MPJ in subflow.c will now be unreachable.

   That's fine, they will be removed in a follow-up patch.

  • In case of conflicting combinations, the extra suboption(s) is/are

   ignored: having such combinations either means the remote peer is

   buggy, or is evil. The simplest action is then taken in this case:

   stop processing the current suboption.

  • In mp_opt->suboptions, there is also a bit reserved to the checksum,

   which can be used in an MP_CAPABLE and a DSS. Each time a DSS option

   can be used in parallel with another option, the checksum can be set,

   so the verification is combined into a new OPTIONSMPTCPDSS macro.

  • An MP_CAPABLE ACK can carry a Data-Level Length, and an optional

   Checksum: they are the same as the ones found in a DSS, because a DSS

   cannot be used in parallel to an MP_CAPABLE. Similarly, even if there

   is room, a DSS cannot be used with an MP_JOIN.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/099bfcbd0c16ae9b50aba2a1bea033e63f895da7, https://git.kernel.org/stable/c/0e2210af439755a2af352eea4178261dcf61742e, https://git.kernel.org/stable/c/6bab907292155513af397a12ccb488acbfc30d79, https://git.kernel.org/stable/c/a04dcc784959e4702048785d87e0d029bd2fbdcb, https://git.kernel.org/stable/c/b6ee361524641f57b2e2363f7737f20e17f67827, https://git.kernel.org/stable/c/dc1d8d3eb345c616fbe922a010fa391c72c54d52, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80587.json, https://nvd.nist.gov/vuln/detail/CVE-2026-80587, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00403%
EPSS Percentile
0.32409%
Introduced Version
eda7acddf8080bb2d022a8d4b8b2345eb80c63ec,5.6.0,5.16.0,6.7.0,6.13.0,6.19.0,0
Fix Available
b6ee361524641f57b2e2363f7737f20e17f67827,5.15.218,6.6.153,6.12.105,6.18.46,7.1.10,6.12.107-1~deb12u1,6.12.105-1,6.8.0-1036.39,0:6.12.0-207.111.5.1.el10uek,0:5.15.0-325.220.5.el8uek,0:6.12.0-207.111.5.1.el9uek,0:5.15.0-325.220.5.el9uek,1:6.18.48-107.148.amzn2023,1:1.0-0.amzn2023,0:5.15.220-153.252.amzn2,0:1.0-0.amzn2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading