PT-2025-25996 · Linux+5 · Linux Kernel+5
Published
2022-08-04
·
Updated
2026-05-26
·
CVE-2022-50070
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.19.0-rc6-g2eae0556bb9d
Description
A vulnerability in the Linux kernel has been resolved, related to the MultiPath TCP (MPTCP) protocol. The issue occurs when an MPTCP-level (re)transmit races with mptcp close() and the packet scheduler checks the subflow state before acquiring the socket lock, allowing data to be queued on closed subflows. The root cause is a race condition between the MPTCP (re)transmit and the mptcp close() function.
Recommendations
For Linux kernel versions prior to 5.19.0-rc6-g2eae0556bb9d, update to a newer version that includes the fix for this issue. As a temporary workaround, consider disabling the MPTCP protocol until a patch is available. Restrict access to the vulnerable MPTCP module to minimize the risk of exploitation. Avoid using the MPTCP protocol in the affected Linux kernel versions until the issue is resolved.
Exploit
Fix
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centos
Debian
Linuxmint
Linux Kernel
Red Hat
Ubuntu