Linux kernel
cpe:2.3:a:linux:linux_kernel:*:*:*:*:*:*:*, +4 more
A vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation has been addressed. The issue was caused by an incorrect handling of address removal logic, specifically in the function responsible for managing addresses via Netlink. The original code only decreased the address removal counter when it was already at zero, indicating an abnormal state, while normal removals were ignored. This vulnerability affects the Linux kernel stable tree.
The vulnerability could lead to improper management of address removal in MPTCP, potentially causing issues in how connections are handled.
Users can download the patched version of the Linux kernel from the Linux kernel stable tree.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.