Impact
In the Linux kernel, the vulnerability stems from a missing restoration of the local_id field when reconstituting a) MP_JOIN request behind SYN cookies. Because the request‑socket slab is not zeroed on allocation, subflow_ulp_clone() reads an uninitialized local_id value that may contain stale data from a previously freed socket. An off‑path peer can influence this value by sending concurrent MP_JOIN SYNs. The corrupted local_id corrupts the path manager’s bookkeeping of subflows, which can lead to traffic disruption or a denial of service for the affected connection.
Affected Systems
This issue affects the Linux kernel’s MPTCP subsystem on any system that enables MPTCP with syncookie support. All versions of the Linux kernel that contain the buggy commit before the patch are vulnerable. The affected, with no specific version identified in the advisory.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity issue, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no publicly known exploits have been confirmed. It is likely that the attack vector requires an off‑path attacker able to inject MP_JOIN SYN impact on subflow management, monitoring for suspicious MPTCP activity is advisable, even though exploitation is considered unlikely.
OpenCVE Enrichment
Debian DSA