Executive brief
The Linux kernel's MPTCP (Multipath TCP) protocol has a race condition between socket disconnect/shutdown and accept operations. An attacker can trigger a NULL pointer dereference that crashes the kernel or causes denial of service, affecting systems that use MPTCP for network communication.
Technical details
The vulnerability is a race condition in mptcp_stream_accept() where a socket can be accepted after mptcp_subflow_queue_clean() releases the listener socket lock but before it completes destructive cleanup actions. The root cause is that the accept path does not acquire the msk-level lock, relying only on the first subflow lock, creating a timing window. An attacker can trigger a NULL pointer dereference (address 0x000000000000012) that causes a kernel panic. The fix removes pending request sockets from the accept queue temporarily during cleanup and reinserts them afterward, preventing the racing accept from accessing partially-cleaned sockets. A patch is available.
Affected products
- Linux Linux kernel 5.x through 6.5.0-rc1
Timeline
- 2023-10-01: disclosed: Published in Linux kernel