CVE-2025-23145
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
01/05/2025
Last modified:
05/11/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mptcp: fix NULL pointer in can_accept_new_subflow<br />
<br />
When testing valkey benchmark tool with MPTCP, the kernel panics in<br />
&#39;mptcp_can_accept_new_subflow&#39; because subflow_req->msk is NULL.<br />
<br />
Call trace:<br />
<br />
mptcp_can_accept_new_subflow (./net/mptcp/subflow.c:63 (discriminator 4)) (P)<br />
subflow_syn_recv_sock (./net/mptcp/subflow.c:854)<br />
tcp_check_req (./net/ipv4/tcp_minisocks.c:863)<br />
tcp_v4_rcv (./net/ipv4/tcp_ipv4.c:2268)<br />
ip_protocol_deliver_rcu (./net/ipv4/ip_input.c:207)<br />
ip_local_deliver_finish (./net/ipv4/ip_input.c:234)<br />
ip_local_deliver (./net/ipv4/ip_input.c:254)<br />
ip_rcv_finish (./net/ipv4/ip_input.c:449)<br />
...<br />
<br />
According to the debug log, the same req received two SYN-ACK in a very<br />
short time, very likely because the client retransmits the syn ack due<br />
to multiple reasons.<br />
<br />
Even if the packets are transmitted with a relevant time interval, they<br />
can be processed by the server on different CPUs concurrently). The<br />
&#39;subflow_req->msk&#39; ownership is transferred to the subflow the first,<br />
and there will be a risk of a null pointer dereference here.<br />
<br />
This patch fixes this issue by moving the &#39;subflow_req->msk&#39; under the<br />
`own_req == true` conditional.<br />
<br />
Note that the !msk check in subflow_hmac_valid() can be dropped, because<br />
the same check already exists under the own_req mpj branch where the<br />
code has been moved to.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.9 (including) | 5.10.237 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.11 (including) | 5.15.181 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.135 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.88 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.24 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.13.12 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.14 (including) | 6.14.3 (excluding) |
| cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/443041deb5ef6a1289a99ed95015ec7442f141dc
- https://git.kernel.org/stable/c/4b2649b9717678aeb097893cc49f59311a1ecab0
- https://git.kernel.org/stable/c/7f9ae060ed64aef8f174c5f1ea513825b1be9af1
- https://git.kernel.org/stable/c/855bf0aacd51fced11ea9aa0d5101ee0febaeadb
- https://git.kernel.org/stable/c/8cf7fef1bb2ffea7792bcbf71ca00216cecc725d
- https://git.kernel.org/stable/c/b3088bd2a6790c8efff139d86d7a9d0b1305977b
- https://git.kernel.org/stable/c/dc81e41a307df523072186b241fa8244fecd7803
- https://git.kernel.org/stable/c/efd58a8dd9e7a709a90ee486a4247c923d27296f
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html



