Fix ID 0 Endpoint Usage after Multiple Re-Creations
CVE-2024-46711

4.7MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
13 September 2024

What is CVE-2024-46711?

In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: fix ID 0 endp usage after multiple re-creations

'local_addr_used' and 'add_addr_accepted' are decremented for addresses not related to the initial subflow (ID0), because the source and destination addresses of the initial subflows are known from the beginning: they don't count as "additional local address being used" or "ADD_ADDR being accepted".

It is then required not to increment them when the entrypoint used by the initial subflow is removed and re-added during a connection. Without this modification, this entrypoint cannot be removed and re-added more than once.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 3ad14f54bd7448384458e69f0183843f683ecce8

Linux 3ad14f54bd7448384458e69f0183843f683ecce8 < 53e2173172d26c0617b29dd83618b71664bed1fb

Linux 3ad14f54bd7448384458e69f0183843f683ecce8 < 119806ae4e46cf239db8e6ad92bc2fd3daae86dc

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.