Impact
A remote peer can send a malformed DSS suboption with an unexpected size to the Linux kernel's Multipath TCP (MPTCP) stack. The kernel ignores the invalid suboption but fails to reset certain internal fields that the malformed data may have touched, leaving them partially initialized or inconsistent. This corrupt state can cause kernel data inconsistencies, a crash, or an uninitialized data read, potentially leading to a denial‑of‑service event.
Affected Systems
The vulnerability affects the MPTCP implementation in the Linux kernel, which is included in all distributions that ship a recent kernel with MPTCP enabled. Any system running an unpatched kernel with MPTCP can be impacted. Specific affected kernel version information is not provided in the CVE data.
Risk and Exploitability
The flaw is exploitable remotely over the network and does not require privileged access. The EPSS score of 0.00404 (below 1%) indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The CVSS score of 9.8 indicates critical severity. An attacker could trigger the inconsistency or crash through carefully crafted packets, posing a high risk to systems with MPTCP enabled.
OpenCVE Enrichment
Debian DLA