CVE-2026-80588: Linux
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mptcp: reclaim forward-allocated memory on RX path errors After commit 9db5b3cec4ec ("mptcp: borrow forward memory from subflow"), errors in the receive path prior to queueing skbs into the receive queue do not trigger forward-allocated memory reclaiming. Prevent forward memory from growing unboundedly in pathological drop scenarios by explicitly reclaiming memory when skbs are dropped.
Affected products
- Linux Linux: from 6.18.35, before 6.18.46 (fixed in 6.18.46); from 6.19, before 7.1.10 (fixed in 7.1.10)
Published 2026-08-26. Last modified 2026-08-27.