KernelScan.io

HIGH Introduced in 4.14

tcp FastPath Bypass

CVE-2026-98255

CVSS 8.1 / 10.0 KernelScan AI

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

01

In the Linux kernel, the following vulnerability has been resolved: tcp: exclude old ACKs from tcp fast path Exclude old ACKs before SND.UNA from the tcp fast path as well as ACKs after SND.NXT. Such ACKs will fall through to the slow path, where tcp_ack() performs the appropriate validation and challenge ACK handling according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not accept ACK of bytes we never sent"). This prevents old ACKs from being accepted or modifying connection state as part of the fast path before appropriate ACK validation is applied. In particular, this prevents payload carried by a segment with an excessively old ACK from advancing RCV.NXT before the ACK is rejected.

02

Engine v0.7.0

Risk summary

A remote attacker who can send crafted TCP segments to a target can exploit a flaw in the TCP fast path to inject data into established TCP connections. The fast path accepted segments with old ACK numbers without proper validation, allowing payload to be processed before the ACK was rejected. This affects any Linux system with TCP network connectivity.

Affectednet/ipv4/tcp_input.c (tcp)

Vulnerability analysis

The TCP fast path in the established receive path only checked that an incoming segment's ACK number did not exceed the next send sequence, but failed to verify it was not older than the oldest unacknowledged sequence. A segment carrying an excessively old ACK could therefore be accepted in the fast path, where its payload would advance the receive window and be delivered to the application before the slow path's ACK validation could reject the invalid ACK. The fix tightens the fast path condition to require the ACK number to fall within the valid send window range; any ACK outside that range now falls through to the slow path where standard RFC 5961 validation and challenge ACK handling apply. This is reachable over the network by any attacker who can deliver TCP segments to the target host, though exploitation requires knowledge of the target connection's sequence numbers, which is trivial for an on-path attacker and difficult but not impossible for an off-path one.

03

BranchIntroducedFixed inPatch commit
5.104.145.10.27107cacab90290
5.154.145.15.2226eb9b697f50b
6.14.146.1.189b86e1e5a4bbc
6.64.146.6.1581c8448db5cf3
6.124.146.12.1128309dc2cc360
6.184.146.18.54ff037920c688
7.24.147.2.88205ac5ddb42
mainline4.147.3-rc4f81e6c3fb063