PT-2024-31363 · Linux+7 · Linux Kernel+7
Published
2024-08-19
·
Updated
2026-05-26
·
CVE-2024-45010
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The issue is related to the Linux kernel's handling of 'subflow' endpoints in the mptcp module. When a 'signal' endpoint is removed, it triggers the removal of all linked subflows via the mptcp pm nl rm addr or subflow() function with rm type == MPTCP MIB RMSUBFLOW. This incorrectly decrements the local addr used counter, which is linked to 'subflow' endpoints. The counter is now decremented only if the ID is used outside of mptcp pm nl rm addr or subflow(), only for 'subflow' endpoints, and if the ID is not 0. The marking of the ID as available and the decrement are done regardless of whether a subflow using this ID is currently available, because the subflow could have been closed before.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu