Description
In the Linux kernel, the following vulnerability has been resolved:

tcp: fix corruption of urgent data on multi-segment retransmit

On the normal xmit path, while in urgent mode we refuse to build a
multi-segment TSO packet, so every segment gets its own urg_ptr:

/* tcp_write_xmit() */
limit = mss_now;
if (tso_segs > 1 && !tcp_urg_mode(tp))
limit = tcp_mss_split_point(...);

The retransmit path has no such guard. __tcp_retransmit_skb() builds a
segs > 1 skb and hands it to the GSO layer, which only advances th->seq
per segment and copies urg_ptr verbatim:

/* __tcp_retransmit_skb() */
len = cur_mss * segs; /* segs > 1, no urg_mode check */
...
/* tcp_gso_segment(): bumps seq only, urg_ptr is copied */

urg_ptr is an offset from the segment's own seq, so a copied value points
at a different place on each segment. The receiver rebuilds the absolute
urgent seq as seg.seq + urg_ptr, so it walks a moving urgent point instead
of the one OOB byte:

seg1 seq 1 urg_ptr 5001 -> urgent @ 5001 (ok)
seg2 seq 1001 urg_ptr 5001 -> urgent @ 6001 (wrong, +MSS)
seg3 seq 2001 urg_ptr 5001 -> urgent @ 7001 (wrong, +2*MSS)

The real OOB byte is never pointed at, so the receiver stops splicing it
out and delivers it as normal in-band data, corrupting the stream.

Guard the retransmit length like the xmit path: keep segs = 1 while in
urgent mode.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Data integrity compromise
Action: Patch
AI Analysis

Impact

A flaw in the Linux kernel’s TCP implementation causes urgent pointer values to be incorrectly copied during retransmission. The retransmit path ignores the guard that the normal path uses when urgent mode is active, allowing a multi‑segment packet to be built with a single urgent pointer that is offset relative to each segment’s sequence number. The receiver then interprets this malformed urgent pointer as a moving point of interest, effectively treating real urgent data as ordinary in‑band data. The consequence is corruption of the data stream, which can lead to application failures, protocol mismatch, and potential exploitation of downstream services that depend on correct urgent data handling. The bug does not provide arbitrary code execution or privilege escalation, but it does weaken data integrity and could serve as a foothold for more complex attacks if combined with other weaknesses.

Affected Systems

The vulnerability impacts all Linux kernel installations that use the standard TCP stack and have not incorporated the fix. It applies to kernel versions prior to the commit that introduced the correct guard on the retransmit path, and it is relevant to every Linux distribution that ships with an unpatched kernel, including Ubuntu, Debian, CentOS, RHEL, Fedora, and others.

Risk and Exploitability

The EPSS score indicates a very low probability of exploitation (<1%). The flaw is not listed in the CISA KEV catalog, implying that no widespread exploitation has been reported. Attackers would need to generate traffic containing urgent data and trigger a retransmission, which is a non‑interactive, network‑based attack vector that is theoretically possible but would require precise conditions and is unlikely to be widely abused. However, the data corruption it causes may produce cascading failures in mission‑critical services. As a result, the risk is moderate for environments that rely on urgent data handling, but low for typical IP traffic patterns where urgent data is rarely used.

Generated by OpenCVE AI on September 20, 2026 at 04:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel package from your distribution that includes the fix (e.g., run your package manager to install the updated kernel image).
  • Reboot the system so that the new kernel is loaded and the network stack uses the corrected code.
  • Enable automated patch management or subscribe to your distribution’s security updates to receive future kernel patches promptly.

Generated by OpenCVE AI on September 20, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: tcp: fix corruption of urgent data on multi-segment retransmit On the normal xmit path, while in urgent mode we refuse to build a multi-segment TSO packet, so every segment gets its own urg_ptr: /* tcp_write_xmit() */ limit = mss_now; if (tso_segs > 1 && !tcp_urg_mode(tp)) limit = tcp_mss_split_point(...); The retransmit path has no such guard. __tcp_retransmit_skb() builds a segs > 1 skb and hands it to the GSO layer, which only advances th->seq per segment and copies urg_ptr verbatim: /* __tcp_retransmit_skb() */ len = cur_mss * segs; /* segs > 1, no urg_mode check */ ... /* tcp_gso_segment(): bumps seq only, urg_ptr is copied */ urg_ptr is an offset from the segment's own seq, so a copied value points at a different place on each segment. The receiver rebuilds the absolute urgent seq as seg.seq + urg_ptr, so it walks a moving urgent point instead of the one OOB byte: seg1 seq 1 urg_ptr 5001 -> urgent @ 5001 (ok) seg2 seq 1001 urg_ptr 5001 -> urgent @ 6001 (wrong, +MSS) seg3 seq 2001 urg_ptr 5001 -> urgent @ 7001 (wrong, +2*MSS) The real OOB byte is never pointed at, so the receiver stops splicing it out and delivers it as normal in-band data, corrupting the stream. Guard the retransmit length like the xmit path: keep segs = 1 while in urgent mode.
Title tcp: fix corruption of urgent data on multi-segment retransmit
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:39.632Z

Reserved: 2026-09-11T19:38:34.783Z

Link: CVE-2026-90054

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:53.873

Modified: 2026-09-17T17:16:53.873

Link: CVE-2026-90054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses

No weakness.