PT-2025-54005 · Linux+1 · Linux Kernel+1
Published
2023-04-13
·
Updated
2026-01-01
·
CVE-2023-54176
CVSS v2.0
5.0
Medium
| Vector | AV:L/AC:H/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.3.0-rc1-gde5e8fd0123c #11
Description
The mptcp protocol could run a worker when the associated socket was in an unexpected state, specifically during a connect operation following an incoming reset and fastclose. This could lead to a divide error and system crash. The issue was identified through a report by Christoph and addressed by implementing stricter state checks before running the mptcp worker.
Recommendations
Update to Linux kernel version 6.3.0-rc1-gde5e8fd0123c #11 or a later version to resolve this issue.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Red Hat