KernelScan.io

HIGH

tcp SynRecv RstBypass

CVE-2026-68118

CVSS 8.2 / 10.0 NVD

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

KernelScan AI7.5HIGH

01

In the Linux kernel, the following vulnerability has been resolved: tcp: challenge ACK for non-exact RST in SYN-RECEIVED The SYN-RECEIVED request-socket path in tcp_check_req() accepts an in-window RST without requiring SEG.SEQ to exactly match RCV.NXT. A non-exact RST therefore removes the request instead of eliciting a challenge ACK. RFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in SYN-RECEIVED: an exact RST resets the connection, while a non-exact in-window RST must trigger a challenge ACK and be dropped. Apply that check before the ACK-field validation, following the RFC sequence-number, RST, then ACK processing order. Factor the per-netns challenge ACK quota out of tcp_send_challenge_ack() so request sockets can share it. Use the request socket's send_ack() callback and its own out-of-window ACK timestamp to send and rate-limit the response.

02

Engine v0.6.0

Risk summary

A blind attacker on the network can send an in-window TCP RST segment to a host with a connection in SYN-RECEIVED state and tear down that connection without knowing the exact receive sequence number. This bypasses the RFC 5961 reset validation that protects established connections, enabling repeated denial of service against new connection establishment. Any networked host that accepts TCP connections is affected; no privileges or local access are required.

Affectednet/ipv4/tcp_minisocks.c (TCP SYN-RECEIVED path)

Vulnerability analysis

The TCP stack's SYN-RECEIVED request-socket path accepts an in-window RST segment without verifying that its sequence number exactly matches the expected receive sequence, so a non-exact RST destroys the pending connection instead of being challenged and dropped. This means a blind attacker who can send TCP packets to the target only needs to guess the receive window — not the precise sequence number — to prematurely terminate half-open connections, bypassing the RFC 5961 protection that already guards established connections. The fix adds the exact-sequence RST check to the SYN-RECEIVED path: a non-exact in-window RST now triggers a rate-limited challenge ACK and is dropped, matching the behavior for established sockets. Any networked host that listens on TCP is reachable; the attacker needs no privileges or local access, only the ability to deliver TCP segments to the target port.

03

BranchIntroducedFixed inPatch commit
6.6—6.6.15322cec809b048
3.23.2.373.30fe4636665d1
3.43.4.253.5234f9ffbd9b2
6.18—6.18.42—
7.1—7.1.6—
mainline—7.2—
6.12—6.12.105a28c4fcbf774
3.03.0.583.18b0a3a094f4c