Sploitus

CVE-2026-63867

No indexed exploits for CVE-2026-63867 yet

In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd The MPTCP output path access locklessly the MPTCP-level ack_seq in multiple times, using possibly different values for the data_ack in the DSS option and to compute the announced rcv wnd for the same packet. Refactor the cote to avoid inconsistencies which may confuse the peer. Also ensure that the MPTCP level rcv wnd is updated only when the egress packet actually contains a DSS ack.

CVSS 3.1
8.2 HIGH
EPSS
0.3% (25th percentile)
NVD status
Awaiting Analysis
Published
2026-07-19
CVE-2026-63867 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-63867 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-63867 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.