Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation has been addressed. The issue arose from improper management of disconnect events generated internally by the MPTCP protocol, particularly in response to FASTOPEN connection errors. This mismanagement led to data stream corruption, as reported by Syzbot. The vulnerability was present in version 6.13.0-rc2.
The vulnerability could be exploited to corrupt data streams, potentially leading to application-level errors or disruptions in communication.
The vulnerability can be reproduced by using the MPTCP protocol with FASTOPEN connections. The improper handling of disconnect events will trigger the data stream corruption.
Users should update to the latest stable version of the Linux kernel where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.