Linux Kernel TCP Fast Open Blackhole Timeout Data Race Vulnerability

Vulnerability

A data race vulnerability has been identified in the Linux kernel's TCP implementation, specifically regarding the sysctl_tcp_fastopen_blackhole_timeout parameter. This vulnerability allows the timeout value to be changed concurrently while it is being read, potentially leading to inconsistent behavior. The issue has been addressed by adding a READ_ONCE() directive to the parameter's readers, ensuring safe access and preventing concurrent modification.

Impact

Exploitation of this vulnerability could lead to data corruption or inconsistent behavior in TCP fast open operations, as concurrent reads and writes to the timeout parameter could cause race conditions.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.