cbcvebase.
CVE-2026-23321
published 2026-03-25

CVE-2026-23321: In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: in-kernel: always mark signal+subflow endp as used Syzkaller managed to find a…

PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.12%
2.4th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: in-kernel: always mark signal+subflow endp as used Syzkaller managed to find a combination of actions that was generating this warning: msk->pm.local_addr_used == 0 WARNING: net/mptcp/pm_kernel.c:1071 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1071 [inline], CPU#1: syz.2.17/961 WARNING: net/mptcp/pm_kernel.c:1071 at mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_kernel.c:1103 [inline], CPU#1: syz.2.17/961 WARNING: net/mptcp/pm_kernel.c:1071 at mptcp_pm_nl_del_addr_doit+0x81d/0x8f0 net/mptcp/pm_kernel.c:1210, CPU#1: syz.2.17/961 Modules linked in: CPU: 1 UID: 0 PID: 961 Comm: syz.2.17 Not tainted 6.19.0-08368-gfafda3b4b06b #22 PREEMPT(full) Hardware name: QEMU Ubuntu 25.10 PC v2 (i440FX + PIIX, + 10.1 machine, 1996), BIOS 1.17.0-debian-1.17.0-1build1 04/01/2014 RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_kernel.c:1071 [inline] RIP: 0010:mptcp_nl_remove_subflow_and_signal_addr net/mptcp/pm_kernel.c:1103 [inline] RIP: 0010:mptcp_pm_nl_del_addr_doit+0x81d/0x8f0 net/mptcp/pm_kernel.c:1210 Code: 89 c5 e8 46 30 6f fe e9 21 fd ff ff 49 83 ed 80 e8 38 30 6f fe 4c 89 ef be 03 00 00 00 e8 db 49 df fe eb ac e8 24 30 6f fe 90 0b 90 e9 1d ff ff ff e8 16 30 6f fe eb 05 e8 0f 30 6f fe e8 9a RSP: 0018:ffffc90001663880 EFLAGS: 00010293 RAX: ffffffff82de1a6c RBX: 0000000000000000 RCX: ffff88800722b500 RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 RBP: ffff8880158b22d0 R08: 0000000000010425 R09: ffffffffffffffff R10: ffffffff82de18ba R11: 0000000000000000 R12: ffff88800641a640 R13: ffff8880158b1880 R14: ffff88801ec3c900 R15: ffff88800641a650 FS: 00005555722c3500(0000) GS:ffff8880f909d000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f66346e0f60 CR3: 000000001607c000 CR4: 0000000000350ef0 Call Trace: genl_family_rcv_msg_doit+0x117/0x180 net/netlink/genetlink.c:1115 genl_family_rcv_msg net/netlink/genetlink.c:1195 [inl

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.19.8-1 (forky)linux 6.19.8-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.1.106 < 6.1.1676.1.167
linuxlinux>= 6.10.5 < 6.116.11
linuxlinux>= 6.6.46 < 6.6.1306.6.130
linuxlinux>= 64815ba15880ce5f99df075fa4104fef170ac7e5 < 05799c2f1ca5eb13d65764dda688d02021b65e0605799c2f1ca5eb13d65764dda688d02021b65e06
linuxlinux>= 85df533a787bf07bf4367ce2a02b822ff1fba1a3 < 67f34ab318807989b57dfdb0f79e2d4e5701829067f34ab318807989b57dfdb0f79e2d4e57018290
linuxlinux>= 85df533a787bf07bf4367ce2a02b822ff1fba1a3 < a64aa7db39392add5be09dffaedbf1f0ce5554dfa64aa7db39392add5be09dffaedbf1f0ce5554df
linuxlinux>= 85df533a787bf07bf4367ce2a02b822ff1fba1a3 < 198824ccfa64ffebd918bf99c939bd8170a4a4d8198824ccfa64ffebd918bf99c939bd8170a4a4d8
linuxlinux>= 85df533a787bf07bf4367ce2a02b822ff1fba1a3 < 579a752464a64cb5f9139102f0e6b90a1f595ceb579a752464a64cb5f9139102f0e6b90a1f595ceb
linuxlinux>= d93cf38fad9f66397093432b8917971a92ee0146 < c5c877e140e5f46023a74a51e577ce5edd0a4be7c5c877e140e5f46023a74a51e577ce5edd0a4be7
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.19.8-16.19.8-1
linuxlinux_kernel>= 0 < 6.1.1676.1.167
linuxlinux_kernel>= 6.1.106 < 6.1.1676.1.167
linuxlinux_kernel>= 6.10.5 < 6.116.11
linuxlinux_kernel>= 6.11.0 < 6.18.176.18.17

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat3.3LOW
vendor_ubuntu2.0LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.