{"api_version":"1","generated_at":"2026-08-12T05:13:00+00:00","cve":"CVE-2026-68118","urls":{"html":"https://cve.report/CVE-2026-68118","api":"https://cve.report/api/cve/CVE-2026-68118.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-68118","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-68118"},"summary":{"title":"tcp: challenge ACK for non-exact RST in SYN-RECEIVED","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: challenge ACK for non-exact RST in SYN-RECEIVED\n\nThe SYN-RECEIVED request-socket path in tcp_check_req() accepts an\nin-window RST without requiring SEG.SEQ to exactly match RCV.NXT.  A\nnon-exact RST therefore removes the request instead of eliciting a\nchallenge ACK.\n\nRFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in\nSYN-RECEIVED: an exact RST resets the connection, while a non-exact\nin-window RST must trigger a challenge ACK and be dropped.\n\nApply that check before the ACK-field validation, following the RFC\nsequence-number, RST, then ACK processing order.  Factor the per-netns\nchallenge ACK quota out of tcp_send_challenge_ack() so request sockets\ncan share it.  Use the request socket's send_ack() callback and its own\nout-of-window ACK timestamp to send and rate-limit the response.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-10 13:19:56","updated_at":"2026-08-10 13:19:56"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/a28c4fcbf774e23b4779cae468e3497a5ad1f4a1","name":"https://git.kernel.org/stable/c/a28c4fcbf774e23b4779cae468e3497a5ad1f4a1","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/22cec809b048495310f206d9abbcdbbfbdce3ae3","name":"https://git.kernel.org/stable/c/22cec809b048495310f206d9abbcdbbfbdce3ae3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/234f9ffbd9b2c1b24ec67200ea3cff07401bec48","name":"https://git.kernel.org/stable/c/234f9ffbd9b2c1b24ec67200ea3cff07401bec48","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-68118","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68118","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 282f23c6ee343126156dd41218b22ece96d747e3 234f9ffbd9b2c1b24ec67200ea3cff07401bec48 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 282f23c6ee343126156dd41218b22ece96d747e3 22cec809b048495310f206d9abbcdbbfbdce3ae3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 282f23c6ee343126156dd41218b22ece96d747e3 a28c4fcbf774e23b4779cae468e3497a5ad1f4a1 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 86791bbfe5ed7b275be040cfeff049a1624af1b7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 61f69dc4e40e41b0018f00fa4aeb23d3239556fb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 34fb350281ced2a72707a5c0064f69992d440edb git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.0.58 3.1 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.2.37 3.3 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.4.25 3.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3.6","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 3.6 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.42 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.6 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2-rc5 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["include/net/tcp.h","net/ipv4/tcp_input.c","net/ipv4/tcp_minisocks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"234f9ffbd9b2c1b24ec67200ea3cff07401bec48","status":"affected","version":"282f23c6ee343126156dd41218b22ece96d747e3","versionType":"git"},{"lessThan":"22cec809b048495310f206d9abbcdbbfbdce3ae3","status":"affected","version":"282f23c6ee343126156dd41218b22ece96d747e3","versionType":"git"},{"lessThan":"a28c4fcbf774e23b4779cae468e3497a5ad1f4a1","status":"affected","version":"282f23c6ee343126156dd41218b22ece96d747e3","versionType":"git"},{"status":"affected","version":"86791bbfe5ed7b275be040cfeff049a1624af1b7","versionType":"git"},{"status":"affected","version":"61f69dc4e40e41b0018f00fa4aeb23d3239556fb","versionType":"git"},{"status":"affected","version":"34fb350281ced2a72707a5c0064f69992d440edb","versionType":"git"},{"lessThan":"3.1","status":"affected","version":"3.0.58","versionType":"semver"},{"lessThan":"3.3","status":"affected","version":"3.2.37","versionType":"semver"},{"lessThan":"3.5","status":"affected","version":"3.4.25","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["include/net/tcp.h","net/ipv4/tcp_input.c","net/ipv4/tcp_minisocks.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"3.6"},{"lessThan":"3.6","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.42","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2-rc5","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.42","versionStartIncluding":"3.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.6","versionStartIncluding":"3.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2-rc5","versionStartIncluding":"3.6","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.58","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.37","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"3.4.25","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: challenge ACK for non-exact RST in SYN-RECEIVED\n\nThe SYN-RECEIVED request-socket path in tcp_check_req() accepts an\nin-window RST without requiring SEG.SEQ to exactly match RCV.NXT.  A\nnon-exact RST therefore removes the request instead of eliciting a\nchallenge ACK.\n\nRFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in\nSYN-RECEIVED: an exact RST resets the connection, while a non-exact\nin-window RST must trigger a challenge ACK and be dropped.\n\nApply that check before the ACK-field validation, following the RFC\nsequence-number, RST, then ACK processing order.  Factor the per-netns\nchallenge ACK quota out of tcp_send_challenge_ack() so request sockets\ncan share it.  Use the request socket's send_ack() callback and its own\nout-of-window ACK timestamp to send and rate-limit the response."}],"providerMetadata":{"dateUpdated":"2026-08-10T11:58:38.000Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/234f9ffbd9b2c1b24ec67200ea3cff07401bec48"},{"url":"https://git.kernel.org/stable/c/22cec809b048495310f206d9abbcdbbfbdce3ae3"},{"url":"https://git.kernel.org/stable/c/a28c4fcbf774e23b4779cae468e3497a5ad1f4a1"}],"title":"tcp: challenge ACK for non-exact RST in SYN-RECEIVED","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-68118","datePublished":"2026-08-10T11:58:38.000Z","dateReserved":"2026-07-30T09:28:09.369Z","dateUpdated":"2026-08-10T11:58:38.000Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-10 13:19:56","lastModifiedDate":"2026-08-10 13:19:56","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"68118","Ordinal":"1","Title":"tcp: challenge ACK for non-exact RST in SYN-RECEIVED","CVE":"CVE-2026-68118","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"68118","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: challenge ACK for non-exact RST in SYN-RECEIVED\n\nThe SYN-RECEIVED request-socket path in tcp_check_req() accepts an\nin-window RST without requiring SEG.SEQ to exactly match RCV.NXT.  A\nnon-exact RST therefore removes the request instead of eliciting a\nchallenge ACK.\n\nRFC 9293 section 3.10.7.4 applies the RFC 5961 reset check in\nSYN-RECEIVED: an exact RST resets the connection, while a non-exact\nin-window RST must trigger a challenge ACK and be dropped.\n\nApply that check before the ACK-field validation, following the RFC\nsequence-number, RST, then ACK processing order.  Factor the per-netns\nchallenge ACK quota out of tcp_send_challenge_ack() so request sockets\ncan share it.  Use the request socket's send_ack() callback and its own\nout-of-window ACK timestamp to send and rate-limit the response.","Type":"Description","Title":"tcp: challenge ACK for non-exact RST in SYN-RECEIVED"}]}}}