PT-2024-3410 · Linux+7 · Linux Kernel+7

Davide Caratti

·

Published

2024-02-26

·

Updated

2025-09-29

·

CVE-2024-26782

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.8.0-rc1+
Description: The vulnerability is related to a double-free issue in the Linux kernel's MPTCP (Multipath TCP) implementation. When an MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet opt' for the new socket has the same value as the original one, leading to a double-free error when the program exits. This can cause a denial-of-service (DoS) condition.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the double-free vulnerability, which is version 6.8.0-rc1 or later. If updating is not possible, consider disabling MPTCP or restricting its use to minimize the risk of exploitation.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-03682
CESA-2024_3618
CVE-2024-26782
DLA-3842-1
DSA-5658-1
DSA-5681-1
INFSA-2024_9315
OESA-2024-1622
OESA-2024-1647
OESA-2024-1648
OESA-2024-1649
OPENSUSE-SU-2024_4314-1
OPENSUSE-SU-2024_4315-1
OPENSUSE-SU-2024_4316-1
OPENSUSE-SU-2024_4346-1
OPENSUSE-SU-2024_4376-1
RHSA-2024:3618
RHSA-2024:9315
RHSA-2024_3618
RHSA-2024_9315
SUSE-SU-2024:4314-1
SUSE-SU-2024:4315-1
SUSE-SU-2024:4316-1
SUSE-SU-2024:4318-1
SUSE-SU-2024:4345-1
SUSE-SU-2024:4346-1
SUSE-SU-2024:4364-1
SUSE-SU-2024:4376-1
SUSE-SU-2024:4387-1
SUSE-SU-2025:20163-1
SUSE-SU-2025:20164-1
SUSE-SU-2025:20246-1
SUSE-SU-2025:20247-1
USN-6820-1
USN-6820-2
USN-6821-1
USN-6821-2
USN-6821-3
USN-6821-4
USN-6828-1
USN-6871-1
USN-6892-1
USN-6895-1
USN-6895-2
USN-6895-3
USN-6895-4
USN-6900-1
USN-6919-1

Affected Products

Astra Linux
Centos
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu