In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. Howev…
Critical CVSS 9.8
Summary
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same value as the original one: as a consequence, on program exit it's possible to observe the following splat: BUG: KASAN: double-free in inet_sock_destruct+0x54f/0x8b0 Free of addr ffff888485950880 by task swapper/25/0 CPU: 25 PID: 0…
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://git.kernel.org/stable/c/10048689def7e40a4405acda16fdc6477d4ecc5c Patch
- https://git.kernel.org/stable/c/4a4eeb6912538c2d0b158e8d11b62d96c1dada4e Patch
- https://git.kernel.org/stable/c/85933e80d077c9ae2227226beb86c22f464059cc Patch
- https://git.kernel.org/stable/c/ce0809ada38dca8d6d41bb57ab40494855c30582 Patch
- https://git.kernel.org/stable/c/d93fd40c62397326046902a2c5cb75af50882a85 Patch
- https://git.kernel.org/stable/c/f74362a004225df935863dea6eb7d82daaa5b16e Patch
- https://git.kernel.org/stable/c/10048689def7e40a4405acda16fdc6477d4ecc5c Patch
- https://git.kernel.org/stable/c/4a4eeb6912538c2d0b158e8d11b62d96c1dada4e Patch
- https://git.kernel.org/stable/c/85933e80d077c9ae2227226beb86c22f464059cc Patch
- https://git.kernel.org/stable/c/ce0809ada38dca8d6d41bb57ab40494855c30582 Patch
- https://git.kernel.org/stable/c/d93fd40c62397326046902a2c5cb75af50882a85 Patch
- https://git.kernel.org/stable/c/f74362a004225df935863dea6eb7d82daaa5b16e Patch
- https://lists.debian.org/debian-lts-announce/2024/06/msg00017.html Mailing List
Timeline
- nvd_ingest NVD