← Back to CVE List

CVE-2024-35840

Published: 2024-05-17T15:15Z
Last Modified: 2024-11-21T09:21Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() subflow_finish_connect() uses four fields (backup, join_id, thmac, none) that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set in mptcp_parse_option() > MITRE Terms of Use apply – see LICENSE‑MITRE.txt