In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".
It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-modules-extraUpgrade kernel-libbpfUpgrade kernel-tools-debuginfoUpgrade python3-perf-debuginfoUpgrade bpftool-debuginfoUpgrade kernel-libbpf-staticUpgrade kernel-debuginfo-common-x86_64Upgrade kernel-headersUpgrade bpftoolUpgrade kernel-toolsUpgrade kernelUpgrade kernel-libbpf-develUpgrade kernel-debuginfo-common-aarch64Upgrade python3-perfUpgrade kernel-modules-extra-commonUpgrade perf-debuginfoUpgrade perfUpgrade kernel-develUpgrade kernel-debuginfoUpgrade kernel-livepatch-6.1.109-118.189Upgrade kernel-tools-devel | Feb 17, 2025 | Sep 13, 2024 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Oct 7, 2024 | Sep 13, 2024 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernelNo solution exists | May 15, 2025 | Sep 13, 2024 |
| Ubuntu | — | Upgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-ibm-classicUpgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-6.8.0-1017-oracle-64kUpgrade linux-image-gkeopUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1018-oemUpgrade linux-image-oem-22.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-genericUpgrade linux-image-generic-64kUpgrade linux-image-raspiUpgrade linux-image-ibmUpgrade linux-image-oem-22.04bUpgrade linux-image-gkeop-6.8Upgrade linux-image-azure-fdeUpgrade linux-image-generic-lpaeUpgrade linux-image-nvidiaUpgrade linux-image-oem-22.04cUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-oracle-64kUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-virtual-hwe-22.04Upgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-azureUpgrade linux-image-lowlatency-64kUpgrade linux-image-nvidia-64kUpgrade linux-image-lowlatencyUpgrade linux-image-oem-22.04aUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-oracleUpgrade linux-image-nvidia-6.8Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-oem-22.04dUpgrade linux-image-6.8.0-1020-awsUpgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-generic-hwe-24.04Upgrade linux-image-gkeUpgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-50-genericUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-awsUpgrade linux-image-kvmUpgrade linux-image-gcpUpgrade linux-image-virtualUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-nvidia-hwe-22.04 | Dec 13, 2024 | Sep 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 13, 2025 | Sep 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub