-

CVE-2026-97566

mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0

In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0

The in-kernel MPTCP path manager can leave a stale ADD_ADDR announcement
entry alive when removing the id 0 endpoint. This happens because the id 0
removal path does not tear down pending announcements, unlike the non-zero
id path.

When the PM later reselects id 0 after adding another signal endpoint, it
finds the stale anno_list entry and hits WARN_ON_ONCE(mptcp_pm_is_kernel())
in mptcp_pm_announced_alloc().

Root cause: asymmetry between removal paths.
- Non-zero id path: mptcp_nl_remove_subflow_and_signal_addr() calls
  mptcp_pm_remove_announced() to clean up.
- Id 0 path: mptcp_nl_remove_id_zero_address() skips cleanup entirely.

Fix by making the id 0 path symmetric: call mptcp_pm_announced_remove()
and decrement add_addr_signaled before queuing the RM_ADDR.

Subtle detail: signal endpoints are stored in anno_list with port 0, but
msk_local carries the connection's local port. In other words, entries
linked to ID0 paths should have port == 0. A follow-up patch will ensure
that. mptcp_pm_announced_remove() uses use_port=true for comparison. So
clear the port before the lookup.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 740d798e8767d8a449902b1a1bbc70facfce19b5
Version < bacf23e7c9876c9f4170166b3597cb22ea3ed39b
Status affected
Version 740d798e8767d8a449902b1a1bbc70facfce19b5
Version < d4a67a880654e1bfe318a31bea0bdbb026a09ade
Status affected
Version 740d798e8767d8a449902b1a1bbc70facfce19b5
Version < 545616b4e7325be3c61fc082538cb06d14f7b1db
Status affected
Version 740d798e8767d8a449902b1a1bbc70facfce19b5
Version < 2ac7d6e620764f1fc79eb4edd3610a7a661981ca
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.13
Status affected
Version 0
Version < 5.13
Status unaffected
Version <= 6.12.*
Version 6.12.112
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.086
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/d4a67a880654e1bfe318a31bea0bdbb026a09ade
https://git.kernel.org/stable/c/545616b4e7325be3c61fc082538cb06d14f7b1db
https://git.kernel.org/stable/c/2ac7d6e620764f1fc79eb4edd3610a7a661981ca
https://git.kernel.org/stable/c/bacf23e7c9876c9f4170166b3597cb22ea3ed39b