In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".
It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-libbpfUpgrade kernel-modules-extraUpgrade bpftoolUpgrade kernel-toolsUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool-debuginfoUpgrade kernel-libbpf-staticUpgrade kernel-libbpf-develUpgrade kernel-tools-debuginfoUpgrade kernelUpgrade python3-perf-debuginfoUpgrade kernel-headersUpgrade kernel-develUpgrade kernel-debuginfoUpgrade perfUpgrade kernel-tools-develUpgrade kernel-modules-extra-commonUpgrade python3-perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-livepatch-6.1.109-118.189Upgrade perf-debuginfo | Feb 17, 2025 | Sep 13, 2024 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Oct 7, 2024 | Sep 13, 2024 |
| Redhat_linux | — | No solution existsUpgrade kernelUpgrade kernel-rt | May 15, 2025 | Sep 13, 2024 |
| Ubuntu | — | Upgrade linux-image-awsUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-6.8.0-50-genericUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-oracleUpgrade linux-image-nvidia-6.8Upgrade linux-image-gkeUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-gcpUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-6.8.0-1020-awsUpgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-oem-22.04dUpgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-kvmUpgrade linux-image-virtualUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-oem-24.04Upgrade linux-image-generic-hwe-22.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-22.04cUpgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-azure-fdeUpgrade linux-image-oracle-64kUpgrade linux-image-raspiUpgrade linux-image-oem-22.04Upgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-genericUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-nvidiaUpgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-6.8.0-1018-oemUpgrade linux-image-generic-64kUpgrade linux-image-ibmUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-oem-22.04bUpgrade linux-image-gkeop-6.8Upgrade linux-image-lowlatencyUpgrade linux-image-oem-22.04aUpgrade linux-image-azureUpgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-6.8.0-1017-oracle-64kUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-gkeopUpgrade linux-image-generic-lpaeUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-lowlatency-64k | Dec 13, 2024 | Sep 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 13, 2025 | Sep 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub