Executive brief
The Linux kernel's TCP-AO (Authentication Option) implementation in standalone TCP response functions leaves uninitialized padding bytes in the TCP header when the MAC length is not aligned to a four-byte boundary. These uninitialized bytes may be transmitted over the network, potentially exposing sensitive kernel memory to remote attackers. This affects systems using TCP-AO for connection authentication.
Technical details
The vulnerability exists in tcp_v4_send_ack() and tcp_v6_send_response() functions, which construct standalone TCP responses with TCP-AO options. When the MAC (Message Authentication Code) length is not aligned to four bytes, the padding bytes between the MAC and the next four-byte boundary are left uninitialized before the MAC is hashed. The tcp_ao_hash_hdr() function writes only the MAC itself, leaving 1–3 bytes of uninitialized memory in the TCP option space that can be transmitted on the network, leaking kernel memory. The fix initializes these padding bytes with TCPOPT_NOP before hashing, ensuring no uninitialized data is sent. This is a memory disclosure vulnerability affecting TCP-AO implementations in the kernel networking stack.
Affected products
- Linux Linux kernel Linux kernels with TCP-AO support (approximately 5.5+)
Timeline
- 2026-08-10: disclosed
- 2026-08-03: patched: Fix committed upstream and backported to stable branches