Junglewise Threat Intelligence

CVE-2026-89554: Linux kernel MPTCP uninitialized local_id in syncookie MP_JOIN reconstruction

CVE-2026-89554 · Severity: high · CVSS 8.2 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's MPTCP (Multipath TCP) protocol implementation contains a bug where an uninitialized field is used when reconstructing connection state from SYN cookies during MP_JOIN (multipath join) requests. An attacker can send concurrent MP_JOIN packets to corrupt the kernel's internal bookkeeping of subflow connections, potentially disrupting multi-path TCP sessions and affecting any service relying on MPTCP for redundant or aggregated network paths.

Technical details

The vulnerability is an uninitialized variable bug in the MPTCP syncookie path. The function mptcp_token_join_cookie_init_state() restores several fields (remote_nonce, local_nonce, backup, join_id, token, msk) from a saved cookie entry when reconstructing a request socket for MP_JOIN 4th-ACK under SYN cookies, but fails to restore the local_id field. The uninitialized local_id is subsequently read by subflow_ulp_clone() and stored as the joined subflow's address-ID. Since the request-sock slab uses SLAB_TYPESAFE_BY_RCU without zeroing allocations, the uninitialized local_id contains stale data from a previously freed request socket. An off-path attacker can influence this stale value by sending concurrent MP_JOIN SYNs, corrupting the path manager's id-based subflow bookkeeping. The fix restores subflow_req->local_id from the cookie entry, consistent with other restored fields. Patches are available in Linux kernel stable trees.

Affected products

  • Linux Linux kernel multiple stable versions (affects MPTCP support across 4.x, 5.x, 6.x, and 7.x series)

Timeline

  • 2026-09-11: disclosed: CVE-2026-89554 published
  • 2026-08-15: patched: Fix committed upstream by Harshit Varu
  • 2026-09-14: other: Patch merged into stable trees by Greg Kroah-Hartman

References

Related threats