Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97523— mptcp: close race between scheduler and state change

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: MPTCP(多路径 TCP):调度器与状态变更之间存在竞争条件 MPTCP 调度器可能与子流套接字的状态变更发生竞争:在选定的套接字上可能发生数据传输失败,且后续的释放操作可能尝试使用 mss_now 重置为 0 的除数进行除法运算。 通过显式检查该关键场景来解决此问题。

CVSS 7.5 · High EPSS 0.67% · P51

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 19

VendorProduct Version RangeStatus
Linux Linux fb9c73ef2ac2ec816efdc8b9267bc04e1369c20b< d74b2e26b54a7dae1d87c1f19ae0d6db500e5e03 affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< 5883ae880f51edc4b1484e787473b865b6159ead affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< 0a926b5df8efdfbac07e2fb7fafb21849a2ad9c0 affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< 8f11430d51ff8365bc51b670bc3002b65ae4c6b7 affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< a09c87abf10a0a7e203137c75b5381aa63d9b31d affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< 4c856f3c151a2f3fa237caa651c44015916ca584 affected
c886d70286bf3ad411eb3d689328a67f7102c6ae< 42064de57fb83231fcc89663a94885f228a1ee53 affected
8caf5c15b5288d52d9c89374d6c10fa32ee84ec5 affected
… +11 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97523

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mptcp: close race between scheduler and state change
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state change The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux fb9c73ef2ac2ec816efdc8b9267bc04e1369c20b ~ d74b2e26b54a7dae1d87c1f19ae0d6db500e5e03 -
Linux Linux 6.0 -

II. Public POCs for CVE-2026-97523

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97523

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97523 (7)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-97578 7.8 HIGH media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-98052 7.8 HIGH net: bcmasp: clear txcb->last before writing each descriptor
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97523

No comments yet


Leave a comment