mptcp: syncookies: remember the request backup flag
Summary
| CVE | CVE-2026-97568 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-25 11:17:07 UTC |
| Updated | 2026-09-25 11:17:07 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: mptcp: syncookies: remember the request backup flag Instead of using an uninitialised bit when copying the info in subflow_ulp_clone(). To fix this, no need to extend the join_entry structure: backup is coming from struct mptcp_subflow_request_sock, only one bit. Do the same here by using one bit for both. |
Risk And Classification
EPSS: 0.002000000 probability, percentile 0.088140000 (date 2026-09-27)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected efd340bf3d7779a3a8ec954d8ec0fb8a10f24982 61178d0b85b4b1b53e78b06e89d018d22d102f88 git | Not specified |
| CNA | Linux | Linux | affected efd340bf3d7779a3a8ec954d8ec0fb8a10f24982 00b2bd518911e0daab00f4749cce68c191ccebb4 git | Not specified |
| CNA | Linux | Linux | affected efd340bf3d7779a3a8ec954d8ec0fb8a10f24982 06d649f9cd03a9f8e768a658b20acf8d2c8022e0 git | Not specified |
| CNA | Linux | Linux | affected efd340bf3d7779a3a8ec954d8ec0fb8a10f24982 b76c0e28b392620dfbaf92cdeedbf115820b44cb git | Not specified |
| CNA | Linux | Linux | affected 1008f2bcbc8e461c1df3aebba30ac4f616ebe570 git | Not specified |
| CNA | Linux | Linux | affected 6f01f41b6a492ddf2da7609967cfaf57e7ca48a7 git | Not specified |
| CNA | Linux | Linux | affected 09176f80995105c62939728fbad5c437d61e7ff4 git | Not specified |
| CNA | Linux | Linux | affected 8ed3e34c766e8264d5d2e0436f86c51604d6a8a7 git | Not specified |
| CNA | Linux | Linux | affected 73e2baa301ee3f62ff971e68877adeb37f98cc67 git | Not specified |
| CNA | Linux | Linux | affected 5.10.224 5.11 semver | Not specified |
| CNA | Linux | Linux | affected 5.15.165 5.16 semver | Not specified |
| CNA | Linux | Linux | affected 6.1.104 6.2 semver | Not specified |
| CNA | Linux | Linux | affected 6.6.45 6.7 semver | Not specified |
| CNA | Linux | Linux | affected 6.10.4 6.11 semver | Not specified |
| CNA | Linux | Linux | affected 6.11 | Not specified |
| CNA | Linux | Linux | unaffected 6.11 semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.111 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.53 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.7 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc3 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/61178d0b85b4b1b53e78b06e89d018d22d102f88 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b76c0e28b392620dfbaf92cdeedbf115820b44cb | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/00b2bd518911e0daab00f4749cce68c191ccebb4 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/06d649f9cd03a9f8e768a658b20acf8d2c8022e0 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.