CVE-2024-35840
May 17, 2024, 6:35 p.m.
Tags
Product(s) Impacted
Linux Kernel
Description
In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() subflow_finish_connect() uses four fields (backup, join_id, thmac, none) that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set in mptcp_parse_option()
Weaknesses
Date
Published: May 17, 2024, 3:15 p.m.
Last Modified: May 17, 2024, 6:35 p.m.
Status : Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
https://git.kernel.org/
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/
416baaa9-dc9f-4396-8d5f-8c081fb06d67
https://git.kernel.org/
416baaa9-dc9f-4396-8d5f-8c081fb06d67