cbcvebase.
CVE-2025-68291
published 2025-12-16

CVE-2025-68291: In the Linux kernel, the following vulnerability has been resolved: mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose()…

PriorityP423medium6.4
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose(). syzbot reported divide-by-zero in __tcp_select_window() by MPTCP socket. [0] We had a similar issue for the bare TCP and fixed in commit 499350a5a6e7 ("tcp: initialize rcv_mss to TCP_MIN_MSS instead of 0"). Let's apply the same fix to mptcp_do_fastclose(). [0]: Oops: divide error: 0000 [#1] SMP KASAN PTI CPU: 0 UID: 0 PID: 6068 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025 RIP: 0010:__tcp_select_window+0x824/0x1320 net/ipv4/tcp_output.c:3336 Code: ff ff ff 44 89 f1 d3 e0 89 c1 f7 d1 41 01 cc 41 21 c4 e9 a9 00 00 00 e8 ca 49 01 f8 e9 9c 00 00 00 e8 c0 49 01 f8 44 89 e0 99 7c 24 1c 41 29 d4 48 bb 00 00 00 00 00 fc ff df e9 80 00 00 00 RSP: 0018:ffffc90003017640 EFLAGS: 00010293 RAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff88807b469e40 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffffc90003017730 R08: ffff888033268143 R09: 1ffff1100664d028 R10: dffffc0000000000 R11: ffffed100664d029 R12: 0000000000000000 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 FS: 000055557faa0500(0000) GS:ffff888126135000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f64a1912ff8 CR3: 0000000072122000 CR4: 00000000003526f0 Call Trace: tcp_select_window net/ipv4/tcp_output.c:281 [inline] __tcp_transmit_skb+0xbc7/0x3aa0 net/ipv4/tcp_output.c:1568 tcp_transmit_skb net/ipv4/tcp_output.c:1649 [inline] tcp_send_active_reset+0x2d1/0x5b0 net/ipv4/tcp_output.c:3836 mptcp_do_fastclose+0x27e/0x380 net/mptcp/protocol.c:2793 mptcp_disconnect+0x238/0x710 net/mptcp/protocol.c:3253 mptcp_sendmsg_fastopen+0x2f8/0x580 net/mptcp/protocol.c:1776 mptcp_sendmsg+0x1774/0x1980 net/mptcp/protocol.c:1855 sock_sendmsg_nosec net/socket.c:727 [inline] __sock_sendmsg+0xe5/0x

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux>= 3a13454fd098ed51e733958488f8ec62859a9ed8 < eee39f83246a81d970a9ecb7392b7ab74e660094eee39f83246a81d970a9ecb7392b7ab74e660094
linuxlinux>= 6.1.159 < 6.1.1606.1.160
linuxlinux>= 6.12.60 < 6.12.616.12.61
linuxlinux>= 6.17.10 < 6.17.116.17.11
linuxlinux>= 6.6.119 < 6.6.1206.6.120
linuxlinux>= 9ea05fabce31ff93a0adae8221c58bc6d7b832f3 < 46b8b58f93f1b383c3840fc6e8fab6c3bce9295f46b8b58f93f1b383c3840fc6e8fab6c3bce9295f
linuxlinux>= ae155060247be8dcae3802a95bd1bdf93ab3215d < f07f4ea53e22429c84b20832fa098b5ecc0d4e35f07f4ea53e22429c84b20832fa098b5ecc0d4e35
linuxlinux>= c4f7b0916b95fd2226e5ab98882482b08f52e1c0 < 88163f85d59b4164884df900ee171720fd26686b88163f85d59b4164884df900ee171720fd26686b
linuxlinux>= f6fb2cbc91a81178dea23d463503b4525a76825d < 05f5e26d488cdc7abc2a826cf1071782d5a2120305f5e26d488cdc7abc2a826cf1071782d5a21203
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.17.11-16.17.11-1
linuxlinux_kernel>= 6.1.159 < 6.1.1606.1.160
linuxlinux_kernel>= 6.12.60 < 6.12.616.12.61
linuxlinux_kernel>= 6.17.10 < 6.17.116.17.11
linuxlinux_kernel>= 6.6.119 < 6.6.1206.6.120
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-6.8
ubuntulinux-azure-fips
ubuntulinux-fips
ubuntulinux-gcp-6.8

CVSS provenance

vendor_ubuntu6.4MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.