-

CVE-2026-80847

Medienbericht

tcp: clamp route advmss to TCP_MIN_MSS

In the Linux kernel, the following vulnerability has been resolved:

tcp: clamp route advmss to TCP_MIN_MSS

tcp_select_initial_window() assumes that callers never pass an MSS
smaller than 1, but route-derived advmss values can violate that
assumption.

A too-small explicit RTAX_ADVMSS is one way to get there, but it is not
the only one. The same divide-by-zero can also be reached through the
"default advmss" path when RTAX_ADVMSS is left at 0 and the effective
advmss is later driven down by route MTU and min_adv_mss.

Introduce a tcp_dst_advmss() helper that clamps route advmss to
TCP_MIN_MSS before TCP consumes it, and use it in the TCP paths that
derive advmss from dst metrics. This keeps the effective MSS from
dropping to zero before tcp_select_initial_window() rounds the receive
window.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < eaf4af9bd6975c2eff8d48820937c83032d968dc
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < cfb44c6028e6f979720315e0772bbd0d4d33ed61
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 6b8c20bf61924dfc38fefb145c9f7406d73fae53
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 31cf2349361902769dc323e4dbf4b449795ec288
Status affected
Version 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Version < 870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.12
Status affected
Version 0
Version < 2.6.12
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.51
Status unaffected
Version <= 7.1.*
Version 7.1.13
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.061
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/6b8c20bf61924dfc38fefb145c9f7406d73fae53
https://git.kernel.org/stable/c/31cf2349361902769dc323e4dbf4b449795ec288
https://git.kernel.org/stable/c/870a9e42ecc6fe1b8c25d87af043cb0d9c178fe1
https://git.kernel.org/stable/c/cfb44c6028e6f979720315e0772bbd0d4d33ed61
https://git.kernel.org/stable/c/eaf4af9bd6975c2eff8d48820937c83032d968dc