Description
In the Linux kernel, the following vulnerability has been resolved:

tcp: fix TFO max_qlen accounting across reuseport migration

A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through
far more pending Fast Open requests than it was configured for.

This only shows up with SO_REUSEPORT listener migration, where closing a
listener hands its still-pending TFO children over to a surviving one.

fastopenq.qlen is charged in tcp_fastopen_create_child() when the child
is created and uncharged in reqsk_fastopen_remove() when the handshake
completes. The uncharge follows rsk_listener of the request the child
points at, and inet_reqsk_clone() has repointed the child at a new
request owned by the new listener, so the ++ and the -- land on two
different sockets. The new listener's qlen drifts negative and its
limit no longer binds.

Charge the new listener during migration, like reqsk_queue_migrated()
already does for queue->young and queue->qlen.
Published: 2026-08-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via unrestricted Fast Open queuing
Action: Patch Immediately
AI Analysis

Impact

The kernel bug miscalculates the TCP Fast Open queue length when a listener socket using SO_REUSEPORT is migrated. The accounting code increases the counter for the new listener while decreasing it for the old one, leaving the counter negative and the limit ineffective. Based on the description, it is inferred that an attacker can provoke such a migration, which would enable the kernel to accept an unchecked number of pending Fast Open connections, exhausting resources and potentially crashing the system.

Affected Systems

Linux kernel builds that enable TCP Fast Open and SO_REUSEPORT are affected. The advisory does not specify exact kernel versions; any distribution that ships the default kernel is potentially vulnerable until the patch is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates moderate to high severity. Public exploitation data is absent and the EPSS score is <1%, suggesting no known exploit in the wild. The likely attack vector is triggering listener migration, typically by restarting or manipulating server processes. Based on the description, it is inferred that this action is required for exploitation, so it is unlikely to be widely exploited. Nonetheless, the unchecked resource allocation provides a clear denial of service vector, and administrators should consider the vulnerability as medium to high risk until a patch is deployed.

Generated by OpenCVE AI on August 25, 2026 at 17:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest kernel version that includes the fix for TFO max_qlen accounting, ensuring the package or source contains the Git commit that implements the corrected accounting during reuseport migration.
  • If a timely kernel upgrade is not yet possible, disable TCP Fast Open on the affected hosts by setting the sysctl net.ipv4.tcp_fastopen to 0 or removing the TCP_fast_open option from application sockets, thereby eliminating the vulnerability’s attack surface.
  • Monitor system logs and connection metrics for abnormal increases in pending Fast Open requests; if such spikes occur, review listener migration patterns and verify that the kernel version is up to date.

Generated by OpenCVE AI on August 25, 2026 at 17:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4777-1 linux security update
Debian DSA Debian DSA DSA-6466-1 linux security update
History

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-191
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 25 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Sat, 22 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-770

Sat, 22 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tcp: fix TFO max_qlen accounting across reuseport migration A listener's TCP_FASTOPEN max_qlen stops being accurate and lets through far more pending Fast Open requests than it was configured for. This only shows up with SO_REUSEPORT listener migration, where closing a listener hands its still-pending TFO children over to a surviving one. fastopenq.qlen is charged in tcp_fastopen_create_child() when the child is created and uncharged in reqsk_fastopen_remove() when the handshake completes. The uncharge follows rsk_listener of the request the child points at, and inet_reqsk_clone() has repointed the child at a new request owned by the new listener, so the ++ and the -- land on two different sockets. The new listener's qlen drifts negative and its limit no longer binds. Charge the new listener during migration, like reqsk_queue_migrated() already does for queue->young and queue->qlen.
Title tcp: fix TFO max_qlen accounting across reuseport migration
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-25T05:41:40.079Z

Reserved: 2026-08-15T05:44:03.926Z

Link: CVE-2026-74696

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-22T16:16:44.153

Modified: 2026-08-25T06:18:53.137

Link: CVE-2026-74696

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-22T00:00:00Z

Links: CVE-2026-74696 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T17:15:05Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)