CVE-2026-97523
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
mptcp: close race between scheduler and state change
The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation.
Address the issue by explicitly checking for the critical scenario.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | c886d70286bf3ad411eb3d689328a67f7102c6ae < 8f11430d51ff8365bc51b670bc3002b65ae4c6b7 | affected |
| Linux | Linux | c886d70286bf3ad411eb3d689328a67f7102c6ae < a09c87abf10a0a7e203137c75b5381aa63d9b31d | affected |
| Linux | Linux | c886d70286bf3ad411eb3d689328a67f7102c6ae < 4c856f3c151a2f3fa237caa651c44015916ca584 | affected |
| Linux | Linux | c886d70286bf3ad411eb3d689328a67f7102c6ae < 42064de57fb83231fcc89663a94885f228a1ee53 | affected |
| Linux | Linux | fb9c73ef2ac2ec816efdc8b9267bc04e1369c20b | affected |
| Linux | Linux | 8caf5c15b5288d52d9c89374d6c10fa32ee84ec5 | affected |
| Linux | Linux | 5.15.190 < 5.16 | affected |
| Linux | Linux | 5.19.4 < 5.20 | affected |
| Linux | Linux | 6.0 | affected |
| Linux | Linux | 0 < 6.0 | unaffected |
| Linux | Linux | 6.12.111 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc4 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/8f11430d51ff8365bc51b670bc3002b65ae4c6b7
- https://git.kernel.org/stable/c/a09c87abf10a0a7e203137c75b5381aa63d9b31d
- https://git.kernel.org/stable/c/4c856f3c151a2f3fa237caa651c44015916ca584
- https://git.kernel.org/stable/c/42064de57fb83231fcc89663a94885f228a1ee53
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.