Linux Kernel TCP Data Race Vulnerability in sysctl_tcp_min_snd_mss

Vulnerability

A data race vulnerability has been identified in the Linux kernel's TCP implementation, specifically regarding the sysctl_tcp_min_snd_mss parameter. This vulnerability arises because the parameter can be modified concurrently while it is being read, potentially leading to inconsistent or unexpected behavior. The issue has been addressed by adding a READ_ONCE() directive to the readers of this parameter, ensuring that reads are performed safely and consistently.

Impact

Exploitation of this vulnerability could lead to data corruption or inconsistent state in TCP connections, as concurrent modifications and reads of the sysctl_tcp_min_snd_mss parameter could interfere with normal TCP operation.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.