PT-2025-3607 · Linux+6 · Linux Kernel+6
Syzbot
·
Published
2024-12-21
·
Updated
2026-02-18
·
CVE-2024-57882
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.6.74
Description
The issue is related to a TCP options overflow in the Linux kernel, specifically in the MPTCP (Multipath TCP) implementation. A buggy MPTCP option length computation can lead to a general protection fault, likely due to a non-canonical address. The root cause is a defective calculation of the MPTCP option length in certain circumstances, where the ADD ADDR option should be mutually exclusive with DSS. This can result in a probable shinfo->nr frags corruption.
Recommendations
To resolve the issue, update the Linux kernel to version 6.6.74 or later. As a temporary workaround, consider disabling the MPTCP functionality until a patch is available. Restrict access to the vulnerable MPTCP module to minimize the risk of exploitation. Avoid using the ADD ADDR option in conjunction with DSS until the issue is resolved.
Exploit
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu