Linux Kernel TCP Data-Race Vulnerability in MTU Probe Floor Handling

Vulnerability

A data-race vulnerability has been identified in the Linux kernel's TCP implementation, specifically regarding the sysctl_tcp_mtu_probe_floor parameter. This vulnerability arises because the parameter can be modified concurrently while it is being read, potentially leading to inconsistent or unexpected behavior. The issue has been addressed by adding a READ_ONCE() directive to the parameter's reader, ensuring that changes are properly synchronized and reducing the risk of concurrent modification issues.

Impact

Exploitation of this vulnerability could lead to a data-race condition, where concurrent read and write operations on the sysctl_tcp_mtu_probe_floor parameter could cause unpredictable behavior in TCP MTU probing, potentially disrupting network performance or reliability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.