Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-97524— mptcp: avoid unneeded actions on subflow reset

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到解决: mptcp:避免在子流重置时执行不必要的操作 偶尔(即极少情况下),在不幸的错误条件下,mptcp 接收路径可能会因状态变更而递归调用 ,随后尝试再次获取数据锁。 通过显式检查异常条件,打破递归循环。 新增一个标志位,而非复用现有标志(如 “closing”),以便在 中提前退出,并在重置时显式刷新接收(RX)队列。 此举可避免对已终止的子流执行不必要的处理,例如检查可用数据(调用 等)、错误报告以及工作队列调度。 请注意,在调用 之前,必须先消耗当前正在探测(peek

CVSS 7.5 · High EPSS 0.69% · P51

Possible ATT&CK Techniques 1 AI

T1068 · Exploitation for Privilege Escalation

Affected Version Matrix 24

VendorProduct Version RangeStatus
Linux Linux fde99e972b8f88cebe619241d7aa43d288ef666a< 6d669c740933124eae3df8cfc15995af9bcc6aba affected
12c1676d598e3b8dd92a033b623b792cc2ea1ec5< 83a7dcdd2b1060484528da70a643125174d47e5a affected
35668f8ec84f6c944676e48ecc6bbc5fc8e6fe25< a370e56024df0b07e3120c45a9773ae123819fd6 affected
b8be15d1ae7ea4eedd547c3b3141f592fbddcd30< 1962841387087970d75ba8b8d4c2aa2d45705e50 affected
e32d262c89e2b22cb0640223f953b548617ed8a6< 4b7abdcb5ba832fafab679f0d998af39cbc99307 affected
e32d262c89e2b22cb0640223f953b548617ed8a6< b2dbcc1ed48b5ac070a41db4a52aade6823c4df0 affected
e32d262c89e2b22cb0640223f953b548617ed8a6< ce7e4ede01ed3e47a48c0f1ce1d87bf4864bee9f affected
e32d262c89e2b22cb0640223f953b548617ed8a6< 2b0f561f21b27c40c91ea4975268a06092bd7e9c affected
… +16 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-97524

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mptcp: avoid unneeded actions on subflow reset
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux fde99e972b8f88cebe619241d7aa43d288ef666a ~ 6d669c740933124eae3df8cfc15995af9bcc6aba -
Linux Linux 6.12 -

II. Public POCs for CVE-2026-97524

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-97524

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-97524 (8)

Same Patch Batch · Linux · 2026-09-25 · 372 CVEs total

CVE-2026-100075 9.8 CRITICAL RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters
CVE-2026-97957 8.8 HIGH net: hinic: fix mailbox segment buffer overflow
CVE-2026-97527 8.8 HIGH scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock
CVE-2026-97528 8.8 HIGH scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error
CVE-2026-97555 8.8 HIGH smb: client: fix heap overflow in DACL owner/group rewrite
CVE-2026-98115 8.8 HIGH ksmbd: safely drain sessions during logoff
CVE-2026-97525 8.2 HIGH x86/mm/pat: Allocate split page tables as kernel page tables
CVE-2026-97573 8.1 HIGH bnxt_en: Handle buffer allocation failure in bnxt_rx_ring_reset()
CVE-2026-97570 8.1 HIGH bnxt_en: Bound SW TPA IDs to prevent crashes
CVE-2026-98070 8.1 HIGH net/rds: acquire RDS_IN_XMIT in rds_tcp_reset_callbacks()
CVE-2026-98069 8.1 HIGH net/rds: acquire the fastpath locks in rds_conn_shutdown()
CVE-2026-98130 8.1 HIGH sctp: fix a TOCTOU race in SCTP_CMD_TIMER_START
CVE-2026-97578 7.8 HIGH media: verisilicon: rockchip: guard VPU981 AV1 divisor and tile buffer
CVE-2026-97548 7.8 HIGH xfs: fix the rtrmap and rtrefcount _maxlevels_ondisk functions
CVE-2026-98052 7.8 HIGH net: bcmasp: clear txcb->last before writing each descriptor
CVE-2026-97611 7.8 HIGH net: openvswitch: fix use-after-free of the flow table mask array
CVE-2026-97612 7.8 HIGH net: mpls: clear inner_protocol when the last label is popped
CVE-2026-98073 7.8 HIGH net: Remove conflicting altnames for dying netns in __dev_change_net_namespace().
CVE-2026-97602 7.8 HIGH inet: frags: invalidate queues before flushing them
CVE-2026-98112 7.8 HIGH ksmbd: fix listener task lifetime on netdev events

Showing top 20 of 372 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-97524

No comments yet


Leave a comment