cbcvebase.
CVE-2025-23145
published 2025-05-01

CVE-2025-23145: In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.53%
41.9th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix NULL pointer in can_accept_new_subflow When testing valkey benchmark tool with MPTCP, the kernel panics in 'mptcp_can_accept_new_subflow' because subflow_req->msk is NULL. Call trace: mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P) subflow_syn_recv_sock (./net/mptcp/subflow.c:854) tcp_check_req (./net/ipv4/tcp_minisocks.c:863) tcp_v4_rcv (./net/ipv4/tcp_ipv4.c:2268) ip_protocol_deliver_rcu (./net/ipv4/ip_input.c:207) ip_local_deliver_finish (./net/ipv4/ip_input.c:234) ip_local_deliver (./net/ipv4/ip_input.c:254) ip_rcv_finish (./net/ipv4/ip_input.c:449) ... According to the debug log, the same req received two SYN-ACK in a very short time, very likely because the client retransmits the syn ack due to multiple reasons. Even if the packets are transmitted with a relevant time interval, they can be processed by the server on different CPUs concurrently). The 'subflow_req->msk' ownership is transferred to the subflow the first, and there will be a risk of a null pointer dereference here. This patch fixes this issue by moving the 'subflow_req->msk' under the `own_req == true` conditional. Note that the !msk check in subflow_hmac_valid() can be dropped, because the same check already exists under the own_req mpj branch where the code has been moved to.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 8cf7fef1bb2ffea7792bcbf71ca00216cecc725d8cf7fef1bb2ffea7792bcbf71ca00216cecc725d
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < b3088bd2a6790c8efff139d86d7a9d0b1305977bb3088bd2a6790c8efff139d86d7a9d0b1305977b
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 855bf0aacd51fced11ea9aa0d5101ee0febaeadb855bf0aacd51fced11ea9aa0d5101ee0febaeadb
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 7f9ae060ed64aef8f174c5f1ea513825b1be9af17f9ae060ed64aef8f174c5f1ea513825b1be9af1
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < dc81e41a307df523072186b241fa8244fecd7803dc81e41a307df523072186b241fa8244fecd7803
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < efd58a8dd9e7a709a90ee486a4247c923d27296fefd58a8dd9e7a709a90ee486a4247c923d27296f
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 4b2649b9717678aeb097893cc49f59311a1ecab04b2649b9717678aeb097893cc49f59311a1ecab0
linuxlinux>= 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 443041deb5ef6a1289a99ed95015ec7442f141dc443041deb5ef6a1289a99ed95015ec7442f141dc
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.9 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3
linuxlinux_kernel>= 6.2 < 6.6.886.6.88

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.