Summary

  • RFC 793 accepted a reset in synchronized states when its sequence number fell within the receive window; RFC 5961 narrowed immediate acceptance to an exact match with RCV.NXT.
  • An in-window but non-exact RST is answered with a challenge ACK and discarded. A real peer can produce confirming state; a blind sender normally cannot.

A forged packet does not need to carry much information to do serious damage. Imagine a long-lived TCP connection and an off-path sender who cannot see its packets. If that sender guesses a sequence number inside the receiver's current window and sets the RST bit, the original RFC 793 rule gave the guess authority to erase the connection. The window was designed to decide whether bytes could belong to the stream. It had become, unintentionally, a credential for a destructive state change.

RFC 5961, published in 2010, did not add encryption or a new handshake. Its repair was smaller and more revealing. An RST outside the receive window is still silently discarded. An RST whose sequence number exactly equals the next expected byte, RCV.NXT, can reset the connection. But an RST that is inside the window without being exact no longer wins. The receiver sends <SEQ=SND.NXT><ACK=RCV.NXT><CTL=ACK>, drops the suspect segment and continues processing later traffic normally.

That packet is called a challenge ACK because it asks the network to turn a claim into evidence. If the remote endpoint genuinely closed or restarted and no longer holds the old transmission control block, its response to the ACK can be a new RST whose sequence number is derived from the acknowledgment. That response can arrive with the exact value the surviving endpoint expects. A blind injector, by contrast, does not observe the challenge and normally cannot convert its rough in-window guess into the exact answer.

The historical importance lies in the distinction between admissibility and authority. A sequence number inside a window is admissible enough to merit a response; it is not authoritative enough to cause an irreversible transition. TCP gained a middle action between “ignore” and “destroy”: challenge, then wait for protocol-consistent evidence.

RFC 5961 applies the same idea to an unexpected SYN in a synchronized state. RFC 793's handling could turn an acceptable SYN into a reset exchange. Under the mitigation, the endpoint sends a challenge ACK regardless of the SYN's sequence number, drops the segment and stops processing it. A spoofed SYN generally produces an extra ACK that the established peer treats as a duplicate. A peer that really restarted has different state and can answer in a way that eventually confirms the old connection should close.

The repair has boundaries. It does not authenticate the sender, and it does not defeat an on-path observer who can see current sequence and acknowledgment state. RFC 5961 also describes a rare restart corner case involving reuse of the same address, port and a particular initial sequence number. The mechanism raises the cost of blind attacks; it does not turn TCP into a cryptographic protocol.

The document also separates recommendation strengths. Its RST and SYN mitigations are recommended, while the stricter ACK-range check for blind data injection is optional. RFC 9293 remains the current base TCP specification and retains the general reset-processing baseline while pointing to RFC 5961 as a robustness enhancement. Protocol history here is layered: the later repair does not pretend the earlier specification never existed.

Primary sources