Description
In the Linux kernel, the following vulnerability has been resolved:

mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction

mptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce,
backup, join_id, token and msk from the saved cookie entry when rebuilding
the request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it
does not restore local_id, even though the SYN path saved it.
subflow_ulp_clone() then reads that uninitialized field and stores it as
the joined subflow's address-ID. Because the request-sock slab is
SLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale
byte of a previously freed request socket, which an off-path peer can
influence by sending concurrent MP_JOIN SYNs. This corrupts the path
manager's id-based subflow bookkeeping for the connection.

Restore subflow_req->local_id from the cookie entry, as done for the other
fields.
Published: 2026-09-11
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Uninitialized local_id leads to subflow ID corruption and potential denial of service.
Action: Patch Kernel
AI Analysis

Impact

In the Linux kernel, the vulnerability stems from a missing restoration of the local_id field when reconstituting a) MP_JOIN request behind SYN cookies. Because the request‑socket slab is not zeroed on allocation, subflow_ulp_clone() reads an uninitialized local_id value that may contain stale data from a previously freed socket. An off‑path peer can influence this value by sending concurrent MP_JOIN SYNs. The corrupted local_id corrupts the path manager’s bookkeeping of subflows, which can lead to traffic disruption or a denial of service for the affected connection.

Affected Systems

This issue affects the Linux kernel’s MPTCP subsystem on any system that enables MPTCP with syncookie support. All versions of the Linux kernel that contain the buggy commit before the patch are vulnerable. The affected, with no specific version identified in the advisory.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity issue, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV, meaning no publicly known exploits have been confirmed. It is likely that the attack vector requires an off‑path attacker able to inject MP_JOIN SYN impact on subflow management, monitoring for suspicious MPTCP activity is advisable, even though exploitation is considered unlikely.

Generated by OpenCVE AI on September 21, 2026 at 00:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kernel to the latest stable release that contains the commit restoring local_id or apply the patch from the provided kernel commit URLs.
  • Disable MPTCP, for example, set sysctl net.mptcp.enable=0 after boot.
  • Monitor system logs for MPTCP and syncookie activity and watch rates that may indicate exploitation attempts.

Generated by OpenCVE AI on September 21, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Sat, 12 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-758

Sat, 12 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H'}

threat_severity

Moderate


Sat, 12 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-758

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction mptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce, backup, join_id, token and msk from the saved cookie entry when rebuilding the request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it does not restore local_id, even though the SYN path saved it. subflow_ulp_clone() then reads that uninitialized field and stores it as the joined subflow's address-ID. Because the request-sock slab is SLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale byte of a previously freed request socket, which an off-path peer can influence by sending concurrent MP_JOIN SYNs. This corrupts the path manager's id-based subflow bookkeeping for the connection. Restore subflow_req->local_id from the cookie entry, as done for the other fields.
Title mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:00:56.863Z

Reserved: 2026-09-11T19:38:34.724Z

Link: CVE-2026-89554

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:39.020

Modified: 2026-09-14T13:19:10.453

Link: CVE-2026-89554

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:44:27Z

Links: CVE-2026-89554 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer