cbcvebase.
CVE-2024-26708
published 2024-04-03

CVE-2024-26708: In the Linux kernel, the following vulnerability has been resolved: mptcp: really cope with fastopen race Fastopen and PM-trigger subflow shutdown can race, as…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.8th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: really cope with fastopen race Fastopen and PM-trigger subflow shutdown can race, as reported by syzkaller. In my first attempt to close such race, I missed the fact that the subflow status can change again before the subflow_state_change callback is invoked. Address the issue additionally copying with all the states directly reachable from TCP_FIN_WAIT1.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.7.7-1 (forky)linux 6.7.7-1 (forky)
linuxlinux
linuxlinux>= 1e777f39b4d75e599a3aac8e0f67d739474f198c < 4bfe217e075d04e63c092df9d40c608e598c2ef24bfe217e075d04e63c092df9d40c608e598c2ef2
linuxlinux>= 1e777f39b4d75e599a3aac8e0f67d739474f198c < e158fb9679d15a2317ec13b4f6301bd26265df2fe158fb9679d15a2317ec13b4f6301bd26265df2f
linuxlinux>= 1e777f39b4d75e599a3aac8e0f67d739474f198c < 337cebbd850f94147cee05252778f8f78b8c337f337cebbd850f94147cee05252778f8f78b8c337f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 0 < 6.7.7-16.7.7-1
linuxlinux_kernel>= 6.2 < 6.6.186.6.18
linuxlinux_kernel>= 6.7 < 6.7.66.7.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.0HIGH
vendor_ubuntu7.0HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.