« Volver al listado

CVE-2026-97524

Estado: RecibidaAlta (7.5)—

In the Linux kernel, the following vulnerability has been resolved:

mptcp: avoid unneeded actions on subflow reset

Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again.

Break the recursion loop explicitly checking for the exceptional condition.

Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time.

This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling.

Leer descripción completaMostrar menos

Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vulnerabilidad de DoS en kernel Linux (AV:N, AC:L, PR:N, UI:N, A:H) por recursión en mptcp_data_ready(). Causa denegación de servicio sin requerir privilegios ni interacción de usuario.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-97524",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "fde99e972b8f88cebe619241d7aa43d288ef666a",
              "lessThan": "6d669c740933124eae3df8cfc15995af9bcc6aba",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "12c1676d598e3b8dd92a033b623b792cc2ea1ec5",
              "lessThan": "83a7dcdd2b1060484528da70a643125174d47e5a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "35668f8ec84f6c944676e48ecc6bbc5fc8e6fe25",
              "lessThan": "a370e56024df0b07e3120c45a9773ae123819fd6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "b8be15d1ae7ea4eedd547c3b3141f592fbddcd30",
              "lessThan": "1962841387087970d75ba8b8d4c2aa2d45705e50",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e32d262c89e2b22cb0640223f953b548617ed8a6",
              "lessThan": "4b7abdcb5ba832fafab679f0d998af39cbc99307",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e32d262c89e2b22cb0640223f953b548617ed8a6",
              "lessThan": "b2dbcc1ed48b5ac070a41db4a52aade6823c4df0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e32d262c89e2b22cb0640223f953b548617ed8a6",
              "lessThan": "ce7e4ede01ed3e47a48c0f1ce1d87bf4864bee9f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e32d262c89e2b22cb0640223f953b548617ed8a6",
              "lessThan": "2b0f561f21b27c40c91ea4975268a06092bd7e9c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8bfd391bde685df7289b928ce8876a3583be4bfb",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.10.228",
              "lessThan": "5.10.271",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.169",
              "lessThan": "5.15.222",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.113",
              "lessThan": "6.1.189",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.57",
              "lessThan": "6.6.158",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.11.4",
              "lessThan": "6.12",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/mptcp/protocol.c",
            "net/mptcp/protocol.h",
            "net/mptcp/subflow.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.271",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.222",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.7",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/mptcp/protocol.c",
            "net/mptcp/protocol.h",
            "net/mptcp/subflow.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-25T11:17:02.520",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1962841387087970d75ba8b8d4c2aa2d45705e50",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2b0f561f21b27c40c91ea4975268a06092bd7e9c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4b7abdcb5ba832fafab679f0d998af39cbc99307",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6d669c740933124eae3df8cfc15995af9bcc6aba",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/83a7dcdd2b1060484528da70a643125174d47e5a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a370e56024df0b07e3120c45a9773ae123819fd6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b2dbcc1ed48b5ac070a41db4a52aade6823c4df0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ce7e4ede01ed3e47a48c0f1ce1d87bf4864bee9f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: avoid unneeded actions on subflow reset\n\nOnce in a blue moon, the mptcp receive path can recursively call\nmptcp_data_ready() via state change under unlucky error conditions, and\nthen try to hold the data lock again.\n\nBreak the recursion loop explicitly checking for the exceptional\ncondition.\n\nAdd a new flag instead of using an existing one like 'closing', to exit\nearly in subflow_state_change(), and explicitly flush the RX queue at\nreset time.\n\nThis avoids unneeded processing to check for available data -- calling\nget_mapping_status() and more on a dying subflow -- but also in error\nreporting and worker scheduling.\n\nNote that we must consume the currently peeked skb before invoking\nmptcp_dss_corruption to avoid consuming it again after the eventual\nreset has freed it."
    }
  ],
  "lastModified": "2026-10-03T11:18:01.307",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}