VDB

CISA-2021-47593

CISA-2021-47593 PUBLISHED

Reported by Linux · Published June 19, 2024

In the Linux kernel, the following vulnerability has been resolved: mptcp: clear 'kern' flag from fallback sockets The mptcp ULP extension relies on sk->sk_sock_kern being set correctly: It prevents setsockopt(fd, IPPROTO_TCP, TCP_ULP, "mptcp", 6); from working for plain tcp sockets (any userspace-exposed socket). But in case of fallback, accept() can return a plain tcp sk. In such case, sk is still tagged as 'kernel' and setsockopt will work. This will crash the kernel, The subflow extension has a NULL ctx->conn mptcp socket: BUG: KASAN: null-ptr-deref in subflow_data_ready+0x181/0x2b0 Call Trace: tcp_data_ready+0xf8/0x370 [..]

Affected Products

VendorProductVersions
LinuxLinuxcf7da0d66cc1a2a19fc5930bb746ffbb2d4cd1be, cf7da0d66cc1a2a19fc5930bb746ffbb2d4cd1be, cf7da0d66cc1a2a19fc5930bb746ffbb2d4cd1be
LinuxLinux5.6, 0, 5.10.88
LinuxLinux5.10.88, 5.6, 5.10.88
linuxlinux_kernel5.6, 5.6, 5.6

Timeline

  • Jun 19, 2024 CVE Published
  • May 4, 2025 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›