CVE-2026-89554
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix uninitialized local_id in syncookie MP_JOIN reconstruction mptcp_token_join_cookie_init_state() restores remote_nonce, local_nonce, backup, join_id, token and msk from the saved cookie entry when rebuilding the request socket for a MP_JOIN 4th-ACK handled under SYN cookies, but it does not restore local_id, even though the SYN path saved it. subflow_ulp_clone() then reads that uninitialized field and stores it as the joined subflow's address-ID. Because the request-sock slab is SLAB_TYPESAFE_BY_RCU and not zeroed on allocation, the value is the stale byte of a previously freed request socket, which an off-path peer can influence by sending concurrent MP_JOIN SYNs. This corrupts the path manager's id-based subflow bookkeeping for the connection. Restore subflow_req->local_id from the cookie entry, as done for the other fields.
What this means for your business
- An attacker can use it remotely, over a network, without a login, and without anyone at your company clicking anything.
- FIRST's prediction model gives it a 0.6% chance of attack attempts being seen in the next 30 days, ranking above 47% of all known flaws.
What to do
- 1Ask your IT team or provider whether any of your systems use the affected product.
- 2If you do, follow the vendor's guidance. No patch reference has been published yet.
Not sure if your company is exposed?
Fastnexa’s certified penetration testers can check whether attackers could use this flaw, or others like it, against your websites, apps and network. The full test is free for our first 10 founding clients until 31 December 2026.
Scoring
- CVSS
- 8.2 (v3.1)
- Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H- Assigned by
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Dates
- Published
- 2026-09-11
- Last modified
- 2026-09-14
- Sources
- NVD
References
- https://git.kernel.org/stable/c/4534e0eead692bb069ad1e6a5a245fc2e2078300
- https://git.kernel.org/stable/c/51887ccd88791ddaa8755a7c614fda031ecf7982
- https://git.kernel.org/stable/c/63cacb05e51a1c6e1349d2e593d00fd6ef43def4
- https://git.kernel.org/stable/c/64f2c5dd49b956a542c8c02b8dad5d262a462bba
- https://git.kernel.org/stable/c/954b5ea836eb118d188975ced803448537ab8479
- https://git.kernel.org/stable/c/9df36a4846375a9b75bf42d77bfed216b0f366f9
- https://git.kernel.org/stable/c/b878dfdd12d7a5b8722a78d35e313506140ca3d9
- https://git.kernel.org/stable/c/bf19d166337c6488b39cb03eeeffb30a941d6326