In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".
It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernelUpgrade kernel-toolsUpgrade kernel-headersUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool-debuginfoUpgrade python3-perf-debuginfoUpgrade bpftoolUpgrade kernel-modules-extraUpgrade kernel-libbpf-develUpgrade kernel-libbpfUpgrade kernel-libbpf-staticUpgrade kernel-tools-debuginfoUpgrade perfUpgrade kernel-modules-extra-commonUpgrade perf-debuginfoUpgrade kernel-develUpgrade kernel-debuginfoUpgrade kernel-livepatch-6.1.109-118.189Upgrade kernel-tools-develUpgrade python3-perfUpgrade kernel-debuginfo-common-aarch64 | Feb 17, 2025 | Sep 13, 2024 |
| Debian | — | Upgrade linuxUpgrade linux-6.1 | Oct 7, 2024 | Sep 13, 2024 |
| Redhat_linux | — | No solution existsUpgrade kernelUpgrade kernel-rt | May 15, 2025 | Sep 13, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1018-oemUpgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-gkeop-6.8Upgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-gkeopUpgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-oem-22.04Upgrade linux-image-azure-fdeUpgrade linux-image-oracle-64kUpgrade linux-image-genericUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-generic-64kUpgrade linux-image-nvidiaUpgrade linux-image-oem-22.04bUpgrade linux-image-ibmUpgrade linux-image-oem-24.04aUpgrade linux-image-oem-22.04cUpgrade linux-image-raspiUpgrade linux-image-generic-lpaeUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-6.8.0-1017-oracle-64kUpgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-lowlatency-64kUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-oem-22.04aUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-lowlatencyUpgrade linux-image-azureUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-gkeUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-oracleUpgrade linux-image-nvidia-6.8Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-gcpUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-kvmUpgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-6.8.0-50-genericUpgrade linux-image-oem-24.04Upgrade linux-image-virtualUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1020-aws | Dec 13, 2024 | Sep 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 13, 2025 | Sep 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub