PT-2024-11251 · Linux+1 · Linux Kernel+1

Maxim Mikityanskiy

·

Published

2021-06-10

·

Updated

2024-11-05

·

CVE-2021-47244

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The TCP option parser in mptcp (mptcp get options) could read one byte out of bounds. When the length is 1, the execution flow gets into the loop, reads one byte of the opcode, and if the opcode is neither TCPOPT EOL nor TCPOPT NOP, it reads one more byte, which exceeds the length of 1. This issue is related to the parsing of TCP options.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-07350
CVE-2021-47244

Affected Products

Astra Linux
Linux Kernel