In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: fix ID 0 endp usage after multiple re-creations
'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".
It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
CVSS Details
- CVSS 3.1 Base Score: 4.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade kernel-debuginfoUpgrade python3-perfUpgrade kernel-debuginfo-common-aarch64Upgrade kernel-tools-develUpgrade kernel-modules-extra-commonUpgrade perf-debuginfoUpgrade kernel-livepatch-6.1.109-118.189Upgrade perfUpgrade kernel-develUpgrade kernel-libbpf-staticUpgrade bpftoolUpgrade kernel-modules-extraUpgrade kernel-libbpf-develUpgrade kernel-tools-debuginfoUpgrade kernelUpgrade kernel-headersUpgrade kernel-debuginfo-common-x86_64Upgrade python3-perf-debuginfoUpgrade kernel-libbpfUpgrade bpftool-debuginfoUpgrade kernel-tools | Feb 17, 2025 | Sep 13, 2024 |
| Debian | — | Upgrade linux-6.1Upgrade linux | Oct 7, 2024 | Sep 13, 2024 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernelNo solution exists | May 15, 2025 | Sep 13, 2024 |
| Ubuntu | — | Upgrade linux-image-ibm-lts-24.04Upgrade linux-image-lowlatency-hwe-22.04Upgrade linux-image-6.8.0-50-genericUpgrade linux-image-nvidia-64k-6.8Upgrade linux-image-nvidia-lowlatency-64kUpgrade linux-image-oem-22.04dUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-generic-64k-hwe-22.04Upgrade linux-image-6.8.0-50-generic-64kUpgrade linux-image-gcpUpgrade linux-image-oracleUpgrade linux-image-nvidia-6.8Upgrade linux-image-6.8.0-50-lowlatencyUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-6.8.0-1017-oracleUpgrade linux-image-virtualUpgrade linux-image-6.8.0-1020-awsUpgrade linux-image-generic-hwe-22.04Upgrade linux-image-nvidia-hwe-22.04Upgrade linux-image-gkeUpgrade linux-image-awsUpgrade linux-image-6.8.0-1019-gcpUpgrade linux-image-kvmUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-oem-24.04Upgrade linux-image-6.8.0-1019-nvidia-64kUpgrade linux-image-6.8.0-1019-nvidiaUpgrade linux-image-nvidia-64kUpgrade linux-image-6.8.0-1002-gkeopUpgrade linux-image-6.8.0-1015-gkeUpgrade linux-image-raspiUpgrade linux-image-ibmUpgrade linux-image-6.8.0-1020-azureUpgrade linux-image-generic-64kUpgrade linux-image-azureUpgrade linux-image-lowlatencyUpgrade linux-image-virtual-hwe-22.04Upgrade linux-image-oem-22.04aUpgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-nvidiaUpgrade linux-image-azure-fdeUpgrade linux-image-oracle-64kUpgrade linux-image-6.8.0-1016-raspiUpgrade linux-image-oem-22.04cUpgrade linux-image-oem-22.04bUpgrade linux-image-genericUpgrade linux-image-gkeop-6.8Upgrade linux-image-oem-22.04Upgrade linux-image-6.8.0-1018-oemUpgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-nvidia-lowlatencyUpgrade linux-image-gkeopUpgrade linux-image-6.8.0-1017-ibmUpgrade linux-image-6.8.0-1020-azure-fdeUpgrade linux-image-6.8.0-1019-nvidia-lowlatencyUpgrade linux-image-lowlatency-64kUpgrade linux-image-nvidia-64k-hwe-22.04Upgrade linux-image-generic-lpaeUpgrade linux-image-lowlatency-64k-hwe-22.04Upgrade linux-image-oem-24.04aUpgrade linux-image-ibm-classicUpgrade linux-image-6.8.0-50-lowlatency-64kUpgrade linux-image-6.8.0-1019-nvidia-lowlatency-64kUpgrade linux-image-6.8.0-1017-oracle-64k | Dec 13, 2024 | Sep 13, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Oct 13, 2025 | Sep 13, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub