CVE-2024-26826 is a moderate-severity Linux kernel flaw in Multipath TCP (MPTCP) that can cause unacknowledged data to be lost when a subflow becomes stale. An invalid optimization invoked a TCP-specific retransmission-queue helper on an MPTCP socket; following a TCP fast-path variable reorganization, the check could skip required data reinjection, creating a denial-of-service condition through lost retransmitted packets. The defect was introduced in kernel version 5.15.
The issue is fixed in stable kernels 5.15.149, 6.1.79, 6.6.18, 6.7.6, and 6.8 and later. Red Hat rated the vulnerability CVSS 3.1 5.5 (moderate), citing local low-complexity exploitation with low privileges and high availability impact, and released updated kernel packages for affected Red Hat Enterprise Linux 8 and 9 systems; RHEL 6 is not affected. Organizations should deploy current vendor kernel updates rather than cherry-picking the individual patch.

See affected versions and whether adversaries are exploiting it.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:4352 with fixed Red Hat Enterprise Linux 8 kernel-rt packages for CVE-2024-26826.
Red Hat released RHSA-2024:4211, providing fixed Red Hat Enterprise Linux 8 kernel packages for CVE-2024-26826.
Red Hat released RHSA-2024:8617 for RHEL 9 kernels and RHSA-2024:8613 and RHSA-2024:8614 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages.
Red Hat released RHSA-2024:6993 with fixed RHEL 8.8 Extended Update Support kernel packages for CVE-2024-26826.
RHSA-2024:5065 delivered fixed RHEL 8.6 kernel packages for Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
The issue was fixed in stable kernel releases 5.15.149, 6.1.79, 6.6.18, 6.7.6, and 6.8. The fix removes the erroneous optimization call from the MPTCP slow path, and the kernel CVE team recommended updating to a current stable release rather than cherry-picking patches.
The Linux kernel CVE team assigned CVE-2024-26826 to an MPTCP flaw in net/mptcp/protocol.c. A TCP-specific retransmission-queue check used on an MPTCP socket could make MPTCP skip required data reinjection.
The MPTCP data-reinjection flaw tracked as CVE-2024-26826 was introduced in Linux kernel 5.15 by commit 1e1d9d6f119c. The defect could cause required reinjection of unacknowledged data to be skipped after a subflow became stale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.