PT-2024-8403 · Linux+5 · Linux Kernel+5

Alexei Starovoitov

·

Published

2024-04-01

·

Updated

2025-09-29

·

CVE-2024-35894

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.8.0-12873-g2c43c33bfd23
Description The issue is caused by the Linux kernel's BPF allowing access to mptcp-level proto ops from a tcp subflow scope. This can lead to a denial of service. The root cause of the issue is that bpf allows accessing mptcp-level proto ops from a tcp subflow scope.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_12746
ALSA-2025_12752
ALSA-2025_12753
ALSA-2025_16880
BDU:2024-09962
CVE-2024-35894
INFSA-2024_9315
RHSA-2024:9315
RHSA-2024_9315
USN-6893-1
USN-6893-2
USN-6893-3
USN-6918-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Hat
Red Os
Ubuntu