CVE-2024-46711
MEDIUMLinux Kernel 6.0-6.1.108, 6.2-6.6.48, 6.7-6.10.7 - Denial of Service via MPTCP Endpoint Re-creation
Title source: llmDescription
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix ID 0 endp usage after multiple re-creations 'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted". It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.
References (5)
Core 5
Core References
Scores
CVSS v3
4.7
EPSS
0.0022
EPSS Percentile
12.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (15)
linux/Kernel
6.0.0 - 6.1.109linux
linux/Kernel
6.2.0 - 6.6.49linux
linux/Kernel
6.7.0 - 6.10.8linux
Linux/Linux
< 6.0
Linux/Linux
3ad14f54bd7448384458e69f0183843f683ecce8 - 119806ae4e46cf239db8e6ad92bc2fd3daae86dc
Linux/Linux
3ad14f54bd7448384458e69f0183843f683ecce8 - 53e2173172d26c0617b29dd83618b71664bed1fb
Linux/Linux
3ad14f54bd7448384458e69f0183843f683ecce8 - 9366922adc6a71378ca01f898c41be295309f044
Linux/Linux
3ad14f54bd7448384458e69f0183843f683ecce8 - c9c744666f7308a4daba520191e29d395260bcfe
Linux/Linux
6.0
Linux/Linux
6.1.109 - 6.1.*
... and 5 more
Published
Sep 13, 2024
Tracked Since
Feb 18, 2026