What is CVE-2026-68118?
A vulnerability in the Linux kernel's TCP stack allows the acceptance of in-window but non-exact RST packets without requiring a challenge ACK in the SYN-RECEIVED request-socket path. This could enable a remote attacker to prematurely terminate connections in the SYN-RECEIVED state, potentially causing a denial of service (DoS). Affected users and administrators should apply the necessary kernel updates.
Azərbaycanca: Linux nüvəsində TCP SYN-RECEIVED vəziyyətində olan sorğu yolu (request-socket path) üçün aşkarlanan zəiflik, pəncərə daxilində olan, lakin tam uyğun olmayan RST paketlərinin challenge ACK tələb etmədən qəbul edilməsinə imkan verir. Bu, uzaqdan hücum edənə SYN-RECEIVED vəziyyətindəki əlaqəni vaxtından əvvəl bağlamaqla xidmətə qarşı imtina (DoS) həyata keçirməsinə şərait yarada bilər. Təsirə məruz qalan sistemlərin istifadəçiləri və administratorları üçün nüvə yeniləmələrini tətbiq etmək tövsiyə olunur.
FAQ2
Which TCP function in the Linux kernel is affected by CVE-2026-68118?
The vulnerability affects the request-socket path in the TCP SYN-RECEIVED state, allowing in-window but non-exact RST packets to be accepted without requiring a challenge ACK.
What can a remote attacker achieve by exploiting CVE-2026-68118?
A remote attacker could prematurely terminate connections in the SYN-RECEIVED state, potentially causing a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.