{"api_version":"1","generated_at":"2026-05-06T13:23:35+00:00","cve":"CVE-2026-43252","urls":{"html":"https://cve.report/CVE-2026-43252","api":"https://cve.report/api/cve/CVE-2026-43252.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-43252","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-43252"},"summary":{"title":"mptcp: pm: in-kernel: always set ID as avail when rm endp","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: in-kernel: always set ID as avail when rm endp\n\nSyzkaller managed to find a combination of actions that was generating\nthis warning:\n\n  WARNING: net/mptcp/pm_kernel.c:1074 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538, CPU#1: syz.7.48/2535\n  Modules linked in:\n  CPU: 1 UID: 0 PID: 2535 Comm: syz.7.48 Not tainted 6.18.0-03987-gea5f5e676cf5 #17 PREEMPT(voluntary)\n  Hardware name: QEMU Ubuntu 25.10 PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n  RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline]\n  RIP: 0010:mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538\n  Code: 89 c7 e8 c5 8c 73 fe e9 f7 fd ff ff 49 83 ef 80 e8 b7 8c 73 fe 4c 89 ff be 03 00 00 00 e8 4a 29 e3 fe eb ac e8 a3 8c 73 fe 90 <0f> 0b 90 e9 3d ff ff ff e8 95 8c 73 fe b8 a1 ff ff ff eb 1a e8 89\n  RSP: 0018:ffffc9001535b820 EFLAGS: 00010287\n  netdevsim0: tun_chr_ioctl cmd 1074025677\n  RAX: ffffffff82da294d RBX: 0000000000000001 RCX: 0000000000080000\n  RDX: ffffc900096d0000 RSI: 00000000000006d6 RDI: 00000000000006d7\n  netdevsim0: linktype set to 823\n  RBP: ffff88802cdb2240 R08: 00000000000104ae R09: ffffffffffffffff\n  R10: ffffffff82da27d4 R11: 0000000000000000 R12: 0000000000000000\n  R13: ffff88801246d8c0 R14: ffffc9001535b8b8 R15: ffff88802cdb1800\n  FS:  00007fc6ac5a76c0(0000) GS:ffff8880f90c8000(0000) knlGS:0000000000000000\n  netlink: 'syz.3.50': attribute type 5 has an invalid length.\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  netlink: 1232 bytes leftover after parsing attributes in process `syz.3.50'.\n  CR2: 0000200000010000 CR3: 0000000025b1a000 CR4: 0000000000350ef0\n  Call Trace:\n   <TASK>\n   mptcp_pm_set_flags net/mptcp/pm_netlink.c:277 [inline]\n   mptcp_pm_nl_set_flags_doit+0x1d7/0x210 net/mptcp/pm_netlink.c:282\n   genl_family_rcv_msg_doit+0x117/0x180 net/netlink/genetlink.c:1115\n   genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n   genl_rcv_msg+0x3a8/0x3f0 net/netlink/genetlink.c:1210\n   netlink_rcv_skb+0x16d/0x240 net/netlink/af_netlink.c:2550\n   genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n   netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n   netlink_unicast+0x3e9/0x4c0 net/netlink/af_netlink.c:1344\n   netlink_sendmsg+0x4ab/0x5b0 net/netlink/af_netlink.c:1894\n   sock_sendmsg_nosec net/socket.c:718 [inline]\n   __sock_sendmsg+0xc9/0xf0 net/socket.c:733\n   ____sys_sendmsg+0x272/0x3b0 net/socket.c:2608\n   ___sys_sendmsg+0x2de/0x320 net/socket.c:2662\n   __sys_sendmsg net/socket.c:2694 [inline]\n   __do_sys_sendmsg net/socket.c:2699 [inline]\n   __se_sys_sendmsg net/socket.c:2697 [inline]\n   __x64_sys_sendmsg+0x110/0x1a0 net/socket.c:2697\n   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0xed/0x360 arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  RIP: 0033:0x7fc6adb66f6d\n  Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\n  RSP: 002b:00007fc6ac5a6ff8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n  RAX: ffffffffffffffda RBX: 00007fc6addf5fa0 RCX: 00007fc6adb66f6d\n  RDX: 0000000000048084 RSI: 00002000000002c0 RDI: 000000000000000e\n  RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000\n---truncated---","state":"PUBLISHED","assigner":"Linux","published_at":"2026-05-06 12:16:45","updated_at":"2026-05-06 13:07:51"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/4d480efd98e290c445f4ba476e4dcda5624b1aab","name":"https://git.kernel.org/stable/c/4d480efd98e290c445f4ba476e4dcda5624b1aab","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1b3ff4d88b508b73e2bbddb59356311efb7ba192","name":"https://git.kernel.org/stable/c/1b3ff4d88b508b73e2bbddb59356311efb7ba192","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7e4d88e36e5d0b8ffda637999cbca64c81701a81","name":"https://git.kernel.org/stable/c/7e4d88e36e5d0b8ffda637999cbca64c81701a81","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d191101dee25567c2af3b28565f45346c33d65f5","name":"https://git.kernel.org/stable/c/d191101dee25567c2af3b28565f45346c33d65f5","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/d90d73ad183566c81320d453a223f610a280f210","name":"https://git.kernel.org/stable/c/d90d73ad183566c81320d453a223f610a280f210","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7c1d221e475e3d8eb8ed4702392d43f8c5134d1f","name":"https://git.kernel.org/stable/c/7c1d221e475e3d8eb8ed4702392d43f8c5134d1f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-43252","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43252","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 027cca7029bee685a5ca5c4849be5a2c446ce046 d90d73ad183566c81320d453a223f610a280f210 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected cb24bdcdecba1c60169efb74d88900888df59907 1b3ff4d88b508b73e2bbddb59356311efb7ba192 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e255683c06df572ead96db5efb5d21be30c0efaa 7c1d221e475e3d8eb8ed4702392d43f8c5134d1f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e255683c06df572ead96db5efb5d21be30c0efaa 7e4d88e36e5d0b8ffda637999cbca64c81701a81 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e255683c06df572ead96db5efb5d21be30c0efaa 4d480efd98e290c445f4ba476e4dcda5624b1aab git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected e255683c06df572ead96db5efb5d21be30c0efaa d191101dee25567c2af3b28565f45346c33d65f5 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 47a049b38f567a2fbec76bc211ad7ad735519607 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.11","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.11 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.167 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.130 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.78 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.16 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.19.6 6.19.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/mptcp/pm_kernel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"d90d73ad183566c81320d453a223f610a280f210","status":"affected","version":"027cca7029bee685a5ca5c4849be5a2c446ce046","versionType":"git"},{"lessThan":"1b3ff4d88b508b73e2bbddb59356311efb7ba192","status":"affected","version":"cb24bdcdecba1c60169efb74d88900888df59907","versionType":"git"},{"lessThan":"7c1d221e475e3d8eb8ed4702392d43f8c5134d1f","status":"affected","version":"e255683c06df572ead96db5efb5d21be30c0efaa","versionType":"git"},{"lessThan":"7e4d88e36e5d0b8ffda637999cbca64c81701a81","status":"affected","version":"e255683c06df572ead96db5efb5d21be30c0efaa","versionType":"git"},{"lessThan":"4d480efd98e290c445f4ba476e4dcda5624b1aab","status":"affected","version":"e255683c06df572ead96db5efb5d21be30c0efaa","versionType":"git"},{"lessThan":"d191101dee25567c2af3b28565f45346c33d65f5","status":"affected","version":"e255683c06df572ead96db5efb5d21be30c0efaa","versionType":"git"},{"status":"affected","version":"47a049b38f567a2fbec76bc211ad7ad735519607","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/mptcp/pm_kernel.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.11"},{"lessThan":"6.11","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.167","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.130","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.78","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.16","versionType":"semver"},{"lessThanOrEqual":"6.19.*","status":"unaffected","version":"6.19.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.0","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.167","versionStartIncluding":"6.1.107","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.130","versionStartIncluding":"6.6.48","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.78","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.16","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.19.6","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0","versionStartIncluding":"6.11","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10.7","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: in-kernel: always set ID as avail when rm endp\n\nSyzkaller managed to find a combination of actions that was generating\nthis warning:\n\n  WARNING: net/mptcp/pm_kernel.c:1074 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538, CPU#1: syz.7.48/2535\n  Modules linked in:\n  CPU: 1 UID: 0 PID: 2535 Comm: syz.7.48 Not tainted 6.18.0-03987-gea5f5e676cf5 #17 PREEMPT(voluntary)\n  Hardware name: QEMU Ubuntu 25.10 PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n  RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline]\n  RIP: 0010:mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538\n  Code: 89 c7 e8 c5 8c 73 fe e9 f7 fd ff ff 49 83 ef 80 e8 b7 8c 73 fe 4c 89 ff be 03 00 00 00 e8 4a 29 e3 fe eb ac e8 a3 8c 73 fe 90 <0f> 0b 90 e9 3d ff ff ff e8 95 8c 73 fe b8 a1 ff ff ff eb 1a e8 89\n  RSP: 0018:ffffc9001535b820 EFLAGS: 00010287\n  netdevsim0: tun_chr_ioctl cmd 1074025677\n  RAX: ffffffff82da294d RBX: 0000000000000001 RCX: 0000000000080000\n  RDX: ffffc900096d0000 RSI: 00000000000006d6 RDI: 00000000000006d7\n  netdevsim0: linktype set to 823\n  RBP: ffff88802cdb2240 R08: 00000000000104ae R09: ffffffffffffffff\n  R10: ffffffff82da27d4 R11: 0000000000000000 R12: 0000000000000000\n  R13: ffff88801246d8c0 R14: ffffc9001535b8b8 R15: ffff88802cdb1800\n  FS:  00007fc6ac5a76c0(0000) GS:ffff8880f90c8000(0000) knlGS:0000000000000000\n  netlink: 'syz.3.50': attribute type 5 has an invalid length.\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  netlink: 1232 bytes leftover after parsing attributes in process `syz.3.50'.\n  CR2: 0000200000010000 CR3: 0000000025b1a000 CR4: 0000000000350ef0\n  Call Trace:\n   <TASK>\n   mptcp_pm_set_flags net/mptcp/pm_netlink.c:277 [inline]\n   mptcp_pm_nl_set_flags_doit+0x1d7/0x210 net/mptcp/pm_netlink.c:282\n   genl_family_rcv_msg_doit+0x117/0x180 net/netlink/genetlink.c:1115\n   genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n   genl_rcv_msg+0x3a8/0x3f0 net/netlink/genetlink.c:1210\n   netlink_rcv_skb+0x16d/0x240 net/netlink/af_netlink.c:2550\n   genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n   netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n   netlink_unicast+0x3e9/0x4c0 net/netlink/af_netlink.c:1344\n   netlink_sendmsg+0x4ab/0x5b0 net/netlink/af_netlink.c:1894\n   sock_sendmsg_nosec net/socket.c:718 [inline]\n   __sock_sendmsg+0xc9/0xf0 net/socket.c:733\n   ____sys_sendmsg+0x272/0x3b0 net/socket.c:2608\n   ___sys_sendmsg+0x2de/0x320 net/socket.c:2662\n   __sys_sendmsg net/socket.c:2694 [inline]\n   __do_sys_sendmsg net/socket.c:2699 [inline]\n   __se_sys_sendmsg net/socket.c:2697 [inline]\n   __x64_sys_sendmsg+0x110/0x1a0 net/socket.c:2697\n   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0xed/0x360 arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  RIP: 0033:0x7fc6adb66f6d\n  Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\n  RSP: 002b:00007fc6ac5a6ff8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n  RAX: ffffffffffffffda RBX: 00007fc6addf5fa0 RCX: 00007fc6adb66f6d\n  RDX: 0000000000048084 RSI: 00002000000002c0 RDI: 000000000000000e\n  RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000\n---truncated---"}],"providerMetadata":{"dateUpdated":"2026-05-06T11:28:42.512Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/d90d73ad183566c81320d453a223f610a280f210"},{"url":"https://git.kernel.org/stable/c/1b3ff4d88b508b73e2bbddb59356311efb7ba192"},{"url":"https://git.kernel.org/stable/c/7c1d221e475e3d8eb8ed4702392d43f8c5134d1f"},{"url":"https://git.kernel.org/stable/c/7e4d88e36e5d0b8ffda637999cbca64c81701a81"},{"url":"https://git.kernel.org/stable/c/4d480efd98e290c445f4ba476e4dcda5624b1aab"},{"url":"https://git.kernel.org/stable/c/d191101dee25567c2af3b28565f45346c33d65f5"}],"title":"mptcp: pm: in-kernel: always set ID as avail when rm endp","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-43252","datePublished":"2026-05-06T11:28:42.512Z","dateReserved":"2026-05-01T14:12:55.996Z","dateUpdated":"2026-05-06T11:28:42.512Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-06 12:16:45","lastModifiedDate":"2026-05-06 13:07:51","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"43252","Ordinal":"1","Title":"mptcp: pm: in-kernel: always set ID as avail when rm endp","CVE":"CVE-2026-43252","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"43252","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: in-kernel: always set ID as avail when rm endp\n\nSyzkaller managed to find a combination of actions that was generating\nthis warning:\n\n  WARNING: net/mptcp/pm_kernel.c:1074 at __mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline], CPU#1: syz.7.48/2535\n  WARNING: net/mptcp/pm_kernel.c:1074 at mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538, CPU#1: syz.7.48/2535\n  Modules linked in:\n  CPU: 1 UID: 0 PID: 2535 Comm: syz.7.48 Not tainted 6.18.0-03987-gea5f5e676cf5 #17 PREEMPT(voluntary)\n  Hardware name: QEMU Ubuntu 25.10 PC (i440FX + PIIX, 1996), BIOS 1.17.0-debian-1.17.0-1 04/01/2014\n  RIP: 0010:__mark_subflow_endp_available net/mptcp/pm_kernel.c:1074 [inline]\n  RIP: 0010:mptcp_pm_nl_fullmesh net/mptcp/pm_kernel.c:1446 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags_all net/mptcp/pm_kernel.c:1474 [inline]\n  RIP: 0010:mptcp_pm_nl_set_flags+0x5de/0x640 net/mptcp/pm_kernel.c:1538\n  Code: 89 c7 e8 c5 8c 73 fe e9 f7 fd ff ff 49 83 ef 80 e8 b7 8c 73 fe 4c 89 ff be 03 00 00 00 e8 4a 29 e3 fe eb ac e8 a3 8c 73 fe 90 <0f> 0b 90 e9 3d ff ff ff e8 95 8c 73 fe b8 a1 ff ff ff eb 1a e8 89\n  RSP: 0018:ffffc9001535b820 EFLAGS: 00010287\n  netdevsim0: tun_chr_ioctl cmd 1074025677\n  RAX: ffffffff82da294d RBX: 0000000000000001 RCX: 0000000000080000\n  RDX: ffffc900096d0000 RSI: 00000000000006d6 RDI: 00000000000006d7\n  netdevsim0: linktype set to 823\n  RBP: ffff88802cdb2240 R08: 00000000000104ae R09: ffffffffffffffff\n  R10: ffffffff82da27d4 R11: 0000000000000000 R12: 0000000000000000\n  R13: ffff88801246d8c0 R14: ffffc9001535b8b8 R15: ffff88802cdb1800\n  FS:  00007fc6ac5a76c0(0000) GS:ffff8880f90c8000(0000) knlGS:0000000000000000\n  netlink: 'syz.3.50': attribute type 5 has an invalid length.\n  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n  netlink: 1232 bytes leftover after parsing attributes in process `syz.3.50'.\n  CR2: 0000200000010000 CR3: 0000000025b1a000 CR4: 0000000000350ef0\n  Call Trace:\n   <TASK>\n   mptcp_pm_set_flags net/mptcp/pm_netlink.c:277 [inline]\n   mptcp_pm_nl_set_flags_doit+0x1d7/0x210 net/mptcp/pm_netlink.c:282\n   genl_family_rcv_msg_doit+0x117/0x180 net/netlink/genetlink.c:1115\n   genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n   genl_rcv_msg+0x3a8/0x3f0 net/netlink/genetlink.c:1210\n   netlink_rcv_skb+0x16d/0x240 net/netlink/af_netlink.c:2550\n   genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219\n   netlink_unicast_kernel net/netlink/af_netlink.c:1318 [inline]\n   netlink_unicast+0x3e9/0x4c0 net/netlink/af_netlink.c:1344\n   netlink_sendmsg+0x4ab/0x5b0 net/netlink/af_netlink.c:1894\n   sock_sendmsg_nosec net/socket.c:718 [inline]\n   __sock_sendmsg+0xc9/0xf0 net/socket.c:733\n   ____sys_sendmsg+0x272/0x3b0 net/socket.c:2608\n   ___sys_sendmsg+0x2de/0x320 net/socket.c:2662\n   __sys_sendmsg net/socket.c:2694 [inline]\n   __do_sys_sendmsg net/socket.c:2699 [inline]\n   __se_sys_sendmsg net/socket.c:2697 [inline]\n   __x64_sys_sendmsg+0x110/0x1a0 net/socket.c:2697\n   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n   do_syscall_64+0xed/0x360 arch/x86/entry/syscall_64.c:94\n   entry_SYSCALL_64_after_hwframe+0x77/0x7f\n  RIP: 0033:0x7fc6adb66f6d\n  Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 90 f3 0f 1e fa 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\n  RSP: 002b:00007fc6ac5a6ff8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\n  RAX: ffffffffffffffda RBX: 00007fc6addf5fa0 RCX: 00007fc6adb66f6d\n  RDX: 0000000000048084 RSI: 00002000000002c0 RDI: 000000000000000e\n  RBP: 0000000000000000 R08: 0000000000000000 R09: 0000000000000000\n  R10: 0000000000000000 R11: 0000000000000246 R12: 000000000000\n---truncated---","Type":"Description","Title":"mptcp: pm: in-kernel: always set ID as avail when rm endp"}]}}}