PT-2026-2887 · Linux+2 · Linux Kernel+2

Published

2025-01-01

·

Updated

2026-06-16

·

CVE-2025-71126

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.18.0-rc7-virtme
Description The Linux kernel contained a flaw in the MPTCP implementation that could lead to a deadlock during fallback when reinjecting packets. This issue occurred when the packet scheduler attempted a reinjection after receiving an MP FAIL signal before the infinite map had been fully transmitted. The deadlock arose because MPTCP required the reinjection process to be atomic from the Write Re-Transmission (WRT) fallback point, and the code could enter a double-lock situation.
Recommendations Update to a version later than 6.18.0-rc7-virtme to resolve this issue.

Exploit

Fix

Improper Locking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03363
CVE-2025-71126
ECHO-8040-85A0-6994
MGASA-2026-0017
MGASA-2026-0018
OPENSUSE-SU-2026:20287-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20555-1
SUSE-SU-2026:20599-1
SUSE-SU-2026:20615-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
USN-8177-1
USN-8177-2
USN-8179-1
USN-8179-2
USN-8179-3
USN-8179-4
USN-8183-1
USN-8183-2
USN-8184-1
USN-8185-1
USN-8185-2
USN-8203-1
USN-8204-1
USN-8245-1
USN-8257-1
USN-8258-1
USN-8260-1
USN-8261-1
USN-8265-1
USN-8440-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu