{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53183","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.390Z","datePublished":"2026-06-25T08:38:57.443Z","dateUpdated":"2026-08-05T12:33:50.018Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:33:50.018Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: allow subflow rcv wnd to shrink\n\nIn MPTCP connection, the `window` field in the TCP header refers to the\nMPTCP-level rcv_nxt and it's right edge should not move backward. Such\nconstraint is enforced at DSS option generation time.\n\nAt the same time, the TCP stack ensures independently that the TCP-level\nrcv wnd right's edge does not move backward. That in turn causes artificial\ninflating of the MPTCP rcv window when the incoming data is acked at the\nTCP level and is OoO in the MPTCP sequence space (or lands in the backlog).\n\nAs a consequence, the incoming traffic can exceed the receiver rcvbuf size\neven when the sender is not misbehaving.\n\nPrevent such scenario forcibly allowing the TCP subflow to shrink the\nTCP-level rcv wnd regardless of the current netns setting."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is reachable through received TCP/MPTCP packets on an established MPTCP connection, including an internet-facing MPTCP-enabled service. The attacker can be a remote MPTCP peer sending crafted valid data patterns.\nAC:L - A peer can intentionally send valid MPTCP data that is out of order in MPTCP sequence space, causing TCP-level ACK/window advancement while MPTCP receive space remains consumed. No race or condition outside the attacker's control is required.\nPR:N - The kernel packet processing path has no privilege or authentication gate once the remote peer establishes an MPTCP connection. Application-level authentication is not required to reach the vulnerable TCP/MPTCP receive and ACK-generation code.\nUI:N - An attacker can target an MPTCP-enabled listener or service directly over the network. No victim user interaction is needed.\nS:U - The impact is within the same kernel/network stack security authority on the affected host. There is no VM escape, sandbox boundary crossing, or separate security scope involved.\nC:N - The bug causes receive-window over-advertisement and excessive receive-buffer consumption, not an out-of-bounds access, use-after-free, or information disclosure primitive. I found no path to reading kernel or application data.\nI:N - The affected logic corrupts flow-control accounting rather than attacker-controlled memory or persistent state. I found no arbitrary write, data modification, or control-flow hijack primitive.\nA:H - A remote peer can drive incoming MPTCP traffic beyond the intended receive-buffer limit, creating kernel socket-buffer memory pressure and denial of service against the host or service. Repeated unauthenticated network triggering makes high availability impact defensible."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mptcp/options.c"],"versions":[{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"bf364b0f10b27679140699821f88af7f01e2a6e3","status":"affected","versionType":"git"},{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"b1fd13074f22105deec45aa02283e322733e0c2d","status":"affected","versionType":"git"},{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"aa3861f40ac32706d9e97bfac76984613e278788","status":"affected","versionType":"git"},{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"653245266913f03fcf21cbca68eed5c197a33e52","status":"affected","versionType":"git"},{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"c297a4e65c50a2b807d9309b22615080faffa8f3","status":"affected","versionType":"git"},{"version":"f3589be0c420a3137e5902d15705ced6a36f3f43","lessThan":"da23be77e1292cd611e736c3aa17da633d7ddce7","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mptcp/options.c"],"versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","status":"unaffected","versionType":"semver"},{"version":"6.1.176","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.143","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.94","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.36","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.13","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.1.176"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.6.143"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.12.94"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.18.36"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.0.13"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/bf364b0f10b27679140699821f88af7f01e2a6e3"},{"url":"https://git.kernel.org/stable/c/b1fd13074f22105deec45aa02283e322733e0c2d"},{"url":"https://git.kernel.org/stable/c/aa3861f40ac32706d9e97bfac76984613e278788"},{"url":"https://git.kernel.org/stable/c/653245266913f03fcf21cbca68eed5c197a33e52"},{"url":"https://git.kernel.org/stable/c/c297a4e65c50a2b807d9309b22615080faffa8f3"},{"url":"https://git.kernel.org/stable/c/da23be77e1292cd611e736c3aa17da633d7ddce7"}],"title":"mptcp: allow subflow rcv wnd to shrink","x_generator":{"engine":"bippy-1.2.0"}}}}