A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.100/6.18.41/7.1.5/7.2-rc4. Affected is the function tcp_v4_send_ack/tcp_v6_send_response of the component TCP-AO. This manipulation causes use of uninitialized variable.

This vulnerability appears as CVE-2026-68119. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.