Impact
This kernel vulnerability arises from a race condition between the disconnect() and rtx events in the MPTCP implementation, potentially leading to inconsistent internal status and system instability. The flaw is a concurrency bug (CWE-362) that can cause denial of service or unpredictable behavior.
Affected Systems
The affected product is the Linux kernel. No specific version range is provided in the CNA data, so any kernel that includes the MPTCP module before the applied fix is potentially vulnerable. Versions from the commit history can be checked against the referenced patches.
Risk and Exploitability
No CVSS score or EPSS value is supplied and the vulnerability is not listed in CISA's KEV catalog. Because the race occurs at kernel level, exploitation would require local privileged access or elevated privileges within the host. The impact is limited to the kernel's MPTCP subsystem, but the lack of publicly available severity metrics suggests a moderate risk that should be mitigated promptly.
OpenCVE Enrichment