๐Ÿ” CVE Alert

CVE-2026-89554

HIGH 8.2

mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction mptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce, backup, join_id, token and msk from the saved cookie entry when rebuilding the request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it does not restore local_id, even though the SYN path saved it. subflow_ulp_clone() then reads that uninitialized field and stores it as the joined subflow's address-ID. Because the request-sock slab is SLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale byte of a previously freed request socket, which an off-path peer can influence by sending concurrent MP_JOIN SYNs. This corrupts the path manager's id-based subflow bookkeeping for the connection. Restore subflow_req->local_id from the cookie entry, as done for the other fields.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 11, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 4534e0eead692bb069ad1e6a5a245fc2e2078300 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 63cacb05e51a1c6e1349d2e593d00fd6ef43def4 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 954b5ea836eb118d188975ced803448537ab8479 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 9df36a4846375a9b75bf42d77bfed216b0f366f9 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 64f2c5dd49b956a542c8c02b8dad5d262a462bba 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < 51887ccd88791ddaa8755a7c614fda031ecf7982 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < bf19d166337c6488b39cb03eeeffb30a941d6326 9466a1ccebbe54ac57fb8a89c2b4b854826546a8 < b878dfdd12d7a5b8722a78d35e313506140ca3d9
Linux / Linux
5.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/4534e0eead692bb069ad1e6a5a245fc2e2078300 git.kernel.org: https://git.kernel.org/stable/c/63cacb05e51a1c6e1349d2e593d00fd6ef43def4 git.kernel.org: https://git.kernel.org/stable/c/954b5ea836eb118d188975ced803448537ab8479 git.kernel.org: https://git.kernel.org/stable/c/9df36a4846375a9b75bf42d77bfed216b0f366f9 git.kernel.org: https://git.kernel.org/stable/c/64f2c5dd49b956a542c8c02b8dad5d262a462bba git.kernel.org: https://git.kernel.org/stable/c/51887ccd88791ddaa8755a7c614fda031ecf7982 git.kernel.org: https://git.kernel.org/stable/c/bf19d166337c6488b39cb03eeeffb30a941d6326 git.kernel.org: https://git.kernel.org/stable/c/b878dfdd12d7a5b8722a78d35e313506140ca3d9