Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

DEBIAN-CVE-2026-80587

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also be...
Back to all
CVE

DEBIAN-CVE-2026-80587

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also be...

In the Linux kernel, the following vulnerability has been resolved:  mptcp: avoid combining some incoming suboptions  Some MPTCP suboptions are mutually exclusive according to the RFC8684, but also because in different places, the code doesn't expect some combinations to be present. That's specially true for suboptions that would be present twice, but with different attributes.  The new restrictions are the same as the ones applied on the output side, with mptcpwriteoptions. The same rules can be reused with a small fix: an MPFASTCLOSE can be used with a DSS when the sender picks this option [1], which is not the case on Linux. Here are the rules:    Which options can be used together?    X: mutually exclusive   O: often used together   C: can be used together in some cases   P: could be used together but we prefer not to (optimisations)    | Opt: | MPC  | MPJ  | DSS  | ADD  |  RM  | PRIO | FAIL |  FC  |   |------|------|------|------|------|------|------|------|------|   | MPC  |------|------|------|------|------|------|------|------|   | MPJ  |  X   |------|------|------|------|------|------|------|   | DSS  |  X   |  X   |------|------|------|------|------|------|   | ADD  |  X   |  X   |  P   |------|------|------|------|------|   | RM   |  C   |  C   |  C   |  P   |------|------|------|------|   | PRIO |  X   |  C   |  C   |  C   |  C   |------|------|------|   | FAIL |  X   |  X   |  C   |  X   |  X   |  X   |------|------|   | FC   |  X   |  X   |  P   |  X   |  X   |  X   |  X   |------|   | RST  |  X   |  X   |  X   |  X   |  X   |  X   |  O   |  O   |   |------|------|------|------|------|------|------|------|------|  The only difference is with the 'P': another stack could send and ADDADDR with other suboptions (DSS, RMADDR), and this should be allowed.  A few points of attention:   - In theory, an MPCAPABLE could be used with a RMADDR, but there is    no reason to add it with a SYN. Note that even with a 4th ACK, it    doesn't seem to be useful, except when IDs are known in advance via    another channel. Better not to break that.   - Now, combining both an MPCAPABLE and an MPJOIN will no longer    result to a reject of the two options, but only the second suboption    is ignored. That seems OK to do that for this unexpected error. At    least now all inconsistent combinations are handled the same way.    This could change later in next. This also means the explicit checks    for having both MPC + MPJ in subflow.c will now be unreachable.    That's fine, they will be removed in a follow-up patch.   - In case of conflicting combinations, the extra suboption(s) is/are    ignored: having such combinations either means the remote peer is    buggy, or is evil. The simplest action is then taken in this case:    stop processing the current suboption.   - In mpopt->suboptions, there is also a bit reserved to the checksum,    which can be used in an MPCAPABLE and a DSS. Each time a DSS option    can be used in parallel with another option, the checksum can be set,    so the verification is combined into a new OPTIONSMPTCPDSS macro.   - An MPCAPABLE ACK can carry a Data-Level Length, and an optional    Checksum: they are the same as the ones found in a DSS, because a DSS    cannot be used in parallel to an MPCAPABLE. Similarly, even if there    is room, a DSS cannot be used with an MPJOIN.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
-
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://security-tracker.debian.org/tracker/CVE-2026-80587

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0%
EPSS Percentile
0%
Introduced Version
0
Fix Available
6.12.105-1,7.1.10-1,6.12.107-1~deb12u1

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading