Junglewise Threat Intelligence

CVE-2026-53183: Linux Kernel resource exhaustion in MPTCP receive window handling

CVE-2026-53183 · Severity: info · CVSS 5.3 · Published 2026-06-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's MultiPath TCP (MPTCP) implementation could allow a remote sender to overwhelm a system's memory buffers. By exploiting how the system tracks data reception across multiple network paths, an attacker could cause the receiver to accept more data than its memory is configured to handle. This can lead to resource exhaustion and potential service instability or crashes.

Technical details

A vulnerability in the Linux kernel's MPTCP implementation arises because the TCP-level receive window right edge is prevented from moving backward, even when MPTCP-level constraints should dictate otherwise. This leads to 'artificial inflating' of the MPTCP receive window when incoming data is acknowledged at the TCP level but remains out-of-order in the MPTCP sequence space or resides in the backlog. Consequently, a sender can transmit data that exceeds the receiver's 'rcvbuf' size. The fix involves forcibly allowing the TCP subflow to shrink the TCP-level receive window during DSS (Data Sequence Signal) option generation in 'net/mptcp/options.c'.

Affected products

  • Linux Linux Kernel 5.19 to 6.18.36

Timeline

  • 2026-06-25: advisory: CVE-2026-53183 published by NVD
  • 2026-06-19: patched: Fix committed to Linux stable branches

References

Related threats