In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".
It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade python3-perfUpgrade kernel-livepatch-6.1.109-118.189Upgrade perfUpgrade kernel-debuginfo-common-aarch64Upgrade perf-debuginfoUpgrade kernel-develUpgrade kernel-modules-extra-commonUpgrade kernel-debuginfoUpgrade kernel-tools-develUpgrade kernel-debuginfo-common-x86_64Upgrade bpftool-debuginfoUpgrade kernel-headersUpgrade kernel-toolsUpgrade kernelUpgrade kernel-libbpf-staticUpgrade kernel-libbpfUpgrade kernel-libbpf-develUpgrade kernel-modules-extraUpgrade kernel-tools-debuginfoUpgrade bpftoolUpgrade python3-perf-debuginfo | Feb 17, 2025 | Sep 13, 2024 |
| Debian | — | Upgrade linuxUpgrade linux-6.1 | Oct 7, 2024 | Sep 13, 2024 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernelNo solution exists | May 15, 2025 | Sep 13, 2024 |
| Ubuntu | — | Upgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-gkeopUpgrade linux-image-oem-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-oem-22.04aUpgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-6.8.0-1018-oemUpgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-oem-22.04cUpgrade linux-image-azureUpgrade linux-image-6.8.0-1017-oracle-64kUpgrade linux-image-lowlatencyUpgrade linux-image-azure-fdeUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-raspiUpgrade linux-image-oracle-64kUpgrade linux-image-ibm-classicUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-genericUpgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-gkeop-6.8Upgrade linux-image-ibmUpgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-oem-24.04aUpgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-nvidiaUpgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-lowlatency-64kUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-oem-22.04bUpgrade linux-image-generic-64kUpgrade linux-image-awsUpgrade linux-image-6.8.0-1020-awsUpgrade linux-image-gcpUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-nvidia-6.8Upgrade linux-image-virtualUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-gkeUpgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-ibm-lts-24.04Upgrade linux-image-nvidia-64k-6.8Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-oem-22.04dUpgrade linux-image-kvmUpgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-6.8.0-50-genericUpgrade linux-image-oracleUpgrade linux-image-oem-24.04Upgrade linux-image-generic-64k-hwe-24.04 | Dec 13, 2024 | Sep 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 13, 2025 | Sep 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub