OSV 1.4.0 · unreviewed · 修改于 2026-08-27 14:31
发布时间
2026-08-27 14:31
GitHub 审查时间
—
NVD 发布时间
2026-08-26 23:17
源文件
advisories/unreviewed/2026/08/GHSA-xhvw-vpqw-3xgx/GHSA-xhvw-vpqw-3xgx.json
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fastopen: only mark MPTFO subflows with SYN data
Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty.
mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SYNs hit a WARN and, if the warning was non-fatal, left stale MPTFO state behind. The stale flag could later trigger a state-confusion bug in check_fully_established().
Only mark the subflow as MPTFO after confirming that an SKB was queued. Return quietly when the receive queue is empty.
Note that mptcp_subflow_context's is_mptfo field is now not just about subflows where the TFO was present, but about MPTFO subflow that consumed SYN data. Only having a valid cookie but not carrying data is not really "doing TFO".
该公告没有提供结构化的受影响软件包信息。