Linux Kernel MPTCP Address Removal Logic Improvement Vulnerability

Vulnerability

A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation has been addressed. The issue was caused by an incorrect handling of address removal logic, specifically in the function responsible for managing addresses via Netlink. The original code only decreased the address removal counter when it was already at zero, indicating an abnormal state, while normal removals were ignored. This vulnerability affects the Linux kernel stable tree.

Impact

The vulnerability could lead to improper management of address removal in MPTCP, potentially causing issues in how connections are handled.

Remediation

Users can download the patched version of the Linux kernel from the Linux kernel stable tree.

Added: Dec 16, 2025, 4:17 PM
Updated: Dec 16, 2025, 4:17 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
0.6
exploitability
5.3
remediation
7.7
relevance
1.4
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.