Junglewise Threat Intelligence

CVE-2023-53490: Linux kernel mptcp disconnect vs accept race condition

CVE-2023-53490 · Severity: high · CVSS 7.8 · Published 2025-10-01

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MPTCP (Multipath TCP) protocol has a race condition between socket disconnect/shutdown and accept operations. An attacker can trigger a NULL pointer dereference that crashes the kernel or causes denial of service, affecting systems that use MPTCP for network communication.

Technical details

The vulnerability is a race condition in mptcp_stream_accept() where a socket can be accepted after mptcp_subflow_queue_clean() releases the listener socket lock but before it completes destructive cleanup actions. The root cause is that the accept path does not acquire the msk-level lock, relying only on the first subflow lock, creating a timing window. An attacker can trigger a NULL pointer dereference (address 0x000000000000012) that causes a kernel panic. The fix removes pending request sockets from the accept queue temporarily during cleanup and reinserts them afterward, preventing the racing accept from accessing partially-cleaned sockets. A patch is available.

Affected products

  • Linux Linux kernel 5.x through 6.5.0-rc1

Timeline

  • 2023-10-01: disclosed: Published in Linux kernel

Related threats