SB2026011407 - Improper locking in Linux kernel mptcp
Published: January 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-71088)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the subflow_state_change() function in net/mptcp/subflow.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/25f1ae942c097b7ae4ce5c2b9c6fefb8e3672b86
- https://git.kernel.org/stable/c/71154bbe49423128c1c8577b6576de1ed6836830
- https://git.kernel.org/stable/c/79f80a7a47849ef1b3c25a0bedcc448b9cb551c1
- https://git.kernel.org/stable/c/b5f46a08269265e2f5e87d855287d6d22de0a32b
- https://git.kernel.org/stable/c/c9bf315228287653522894df9d851e9b43db9516