CVE-2026-80585 evidence review
Linux
In the Linux kernel, the following vulnerability has been resolved: mptcp: fastopen: only mark MPTFO subflows with SYN data Passive TCP Fast Open accepts a valid-cookie SYN even when it carries no data. In that case the child socket's receive queue is intentionally left empty. mptcp_fastopen_subflow_synack_set_params() set is_mptfo before checking for queued SYN data. That made data-less TFO SYNs hit a WARN and, if the warning was non-fatal, left stale MPTFO state behind. The stale flag could later trigger a state-confusion bug in check_fully_established(). Only mark the subflow as MPTFO af...
This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.
Identify the product and installed version
Record whether Linux is present, where it is installed, and which interfaces are exposed.
- Record the product name, package or appliance identifier, and installed version.
- Identify internet-facing, administrative, API, and internal access paths.
- Preserve the pre-change configuration and relevant service logs.
Compare the affected range
Use the current record as an identification aid: >= 36b122baf6a8bd46b4a591f12f4ed17b22257408 < f75f174edc865738522e514d042cf5627f084859, >= 36b122baf6a8bd46b4a591f12f4ed17b22257408 < fca7e444c04689fe4cc6b56f2725f804a4bb1ef9, >= 36b122baf6a8bd46b4a591f12f4ed17b22257408 < 75e564b2ced1cc3d9a8904c7d2d2bb448fffb8b5, >= 36b122baf6a8bd46b4a591f12f4ed17b22257408 < 72b4a0c51a4b550d40301d60a366b429b8c8e78d, >= 36b122baf6a8bd46b4a591f12f4ed17b22257408 < e00b63056fb4f261455b3e5df5268a1f8ce47a87, >= 6.2. Resolve incomplete inventory results before deciding that an asset is unaffected.
Verify the authoritative remediation source
Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.
Operational boundary
This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.