SB2025050493 - Improper resource shutdown or release in Linux kernel mptcp
Published: May 4, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper resource shutdown or release (CVE-ID: CVE-2023-53072)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to failure to properly release resources within the subflow_hmac_valid(), subflow_ulp_fallback(), mptcp_subflow_queue_clean() and subflow_ulp_release() functions in net/mptcp/subflow.c, within the __mptcp_close_ssk(), mptcp_sync_mss(), __mptcp_close_subflow(), mptcp_worker(), mptcp_sk_clone(), mptcp_accept() and mptcp_stream_accept() functions in net/mptcp/protocol.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2827f099b3fb9a59263c997400e9182f5d423e84
- https://git.kernel.org/stable/c/804cf487fb0031f3c74755b78d8663333f0ba636
- https://git.kernel.org/stable/c/b6985b9b82954caa53f862d6059d06c0526254f0
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.22
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.3