Answer in brief
CVE-2026-80585 records a Unknown severity vulnerability in mptcp: fastopen: only mark MPTFO subflows with SYN data. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=36b122baf6a8bd46b4a591f12f4ed17b22257408 <f75f174edc865738522e514d042cf5627f084859 || >=36b122baf6a8bd46b4a591f12f4ed17b22257408 <fca7e444c04689fe4cc6b56f2725f804a4bb1ef9 || >=36b122baf6a8bd46b4a591f12f4ed17b22257408 <75e564b2ced1cc3d9a8904c7d2d2bb448fffb8b5 || >=36b122baf6a8bd46b4a591f12f4ed17b22257408 <72b4a0c51a4b550d40301d60a366b429b8c8e78d || >=36b122baf6a8bd46b4a591f12f4ed17b22257408 <e00b63056fb4f261455b3e5df5268a1f8ce47a87 | f75f174edc865738522e514d042cf5627f084859, fca7e444c04689fe4cc6b56f2725f804a4bb1ef9, 75e564b2ced1cc3d9a8904c7d2d2bb448fffb8b5, 72b4a0c51a4b550d40301d60a366b429b8c8e78d, e00b63056fb4f261455b3e5df5268a1f8ce47a87 |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 26, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 26, 2026
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SYNs hit a WARN and, if the warning was non-fatal, left stale MPTFO state behind. The stale flag could later trigger a state-confusion bug in check_fully_established(). Only mark the subflow as MPTFO after confirming that an SKB was queued. Return quietly when the receive queue is empty. Note that mptcp_subflow_context's is_mptfo field is now not just about subflows where the TFO was present, but about MPTFO subflow that consumed SYN data. Only having a valid cookie but not carrying data is not really "doing TFO".
Quoted source text, attributed separately from HOL analysis.