cbcvebase.
CVE-2024-46711
published 2024-09-13

CVE-2024-46711: In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix ID 0 endp usage after multiple re-creations 'local_addr_used' and…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.22%
12.2th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix ID 0 endp usage after multiple re-creations 'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted". It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
debianlinux-6.1< linux 6.1.112-1 (bookworm)linux 6.1.112-1 (bookworm)
linuxlinux
linuxlinux>= 3ad14f54bd7448384458e69f0183843f683ecce8 < c9c744666f7308a4daba520191e29d395260bcfec9c744666f7308a4daba520191e29d395260bcfe
linuxlinux>= 3ad14f54bd7448384458e69f0183843f683ecce8 < 53e2173172d26c0617b29dd83618b71664bed1fb53e2173172d26c0617b29dd83618b71664bed1fb
linuxlinux>= 3ad14f54bd7448384458e69f0183843f683ecce8 < 119806ae4e46cf239db8e6ad92bc2fd3daae86dc119806ae4e46cf239db8e6ad92bc2fd3daae86dc
linuxlinux>= 3ad14f54bd7448384458e69f0183843f683ecce8 < 9366922adc6a71378ca01f898c41be295309f0449366922adc6a71378ca01f898c41be295309f044
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.112-16.1.112-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.10.9-16.10.9-1
linuxlinux_kernel>= 0 < 6.8.0-50.516.8.0-50.51
linuxlinux_kernel>= 6.0 < 6.1.1096.1.109
linuxlinux_kernel>= 6.2 < 6.6.496.6.49
linuxlinux_kernel>= 6.7 < 6.10.86.10.8
msrcazl3_kernel_6.6.47.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.51.1-5_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.