CVE-2025-71144: mptcp: ensure context reset on disconnect()

Published Jan 14, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

mptcp: ensure context reset on disconnect()

After the blamed commit below, if the MPC subflow is already in TCPCLOSE status or has fallback to TCP at mptcpdisconnect() time, mptcpdofastclose() skips setting the sendfastclose flag and the later mptcpclosessk() does not reset anymore the related subflow context.

Any later connection will be created with both the requestmptcp flag and the msk-level fallback status off (it is unconditionally cleared at MPTCP disconnect time), leading to a warning in subflowdataready():

WARNING: CPU: 26 PID: 8996 at net/mptcp/subflow.c:1519 subflowdataready (net/mptcp/subflow.c:1519 (discriminator 13)) Modules linked in: CPU: 26 UID: 0 PID: 8996 Comm: syz.22.39 Not tainted 6.18.0-rc7-05427-g11fc074f6c36 #1 PREEMPT(voluntary) Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 RIP: 0010:subflowdataready (net/mptcp/subflow.c:1519 (discriminator 13)) Code: 90 0f 0b 90 90 e9 04 fe ff ff e8 b7 1e f5 fe 89 ee bf 07 00 00 00 e8 db 19 f5 fe 83 fd 07 0f 84 35 ff ff ff e8 9d 1e f5 fe 90 <0f> 0b 90 e9 27 ff ff ff e8 8f 1e f5 fe 4c 89 e7 48 89 de e8 14 09 RSP: 0018:ffffc9002646fb30 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff88813b218000 RCX: ffffffff825c8435 RDX: ffff8881300b3580 RSI: ffffffff825c8443 RDI: 0000000000000005 RBP: 000000000000000b R08: ffffffff825c8435 R09: 000000000000000b R10: 0000000000000005 R11: 0000000000000007 R12: ffff888131ac0000 R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000 FS: 00007f88330af6c0(0000) GS:ffff888a93dd2000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f88330aefe8 CR3: 000000010ff59000 CR4: 0000000000350ef0 Call Trace: <TASK> tcpdataready (net/ipv4/tcpinput.c:5356) tcpdataqueue (net/ipv4/tcpinput.c:5445) tcprcvstateprocess (net/ipv4/tcpinput.c:7165) tcpv4dorcv (net/ipv4/tcpipv4.c:1955) releasesock (include/net/sock.h:1158 (discriminator 6) net/core/sock.c:3180 (discriminator 6)) releasesock (net/core/sock.c:3737) mptcpsendmsg (net/mptcp/protocol.c:1763 net/mptcp/protocol.c:1857) inetsendmsg (net/ipv4/afinet.c:853 (discriminator 7)) syssendto (net/socket.c:727 (discriminator 15) net/socket.c:742 (discriminator 15) net/socket.c:2244 (discriminator 15)) x64syssendto (net/socket.c:2247) dosyscall64 (arch/x86/entry/syscall64.c:63 (discriminator 1) arch/x86/entry/syscall64.c:94 (discriminator 1)) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:130) RIP: 0033:0x7f883326702d

Address the issue setting an explicit fastclosing flag at fastclose time, and checking such flag after mptcpdofastclose().

Affected Software

11 affected components
linux_kernel
Linux Linux kernel>=6.1.159<6.1.164
Linux Linux kernel>=6.12.60<6.12.65
Linux Linux kernel>=6.17.10<6.18
Linux Linux kernel>=6.18.1<6.18.5
Linux Linux kernel=6.6.119
Linux Linux kernel=6.18
Linux Linux kernel=6.18-rc7
Linux Linux kernel=6.19-rc1
Linux Linux kernel=6.19-rc2
Linux Linux kernel=6.19-rc3

Event History

Jan 14, 2026
CVE Published
via MITRE·03:08 PM
Data Sourced
via MITRE·03:08 PM
Description
Data Sourced
via NVD·03:16 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-71144?

CVE-2025-71144 is classified as a moderate severity vulnerability due to its potential impact on MPTCP context management.

2

How do I fix CVE-2025-71144?

To fix CVE-2025-71144, ensure you update your Linux kernel to the version that includes the patch addressing this vulnerability.

3

Who is affected by CVE-2025-71144?

Users running the affected versions of the Linux kernel that utilize MPTCP may be vulnerable to CVE-2025-71144.

4

What type of vulnerability is CVE-2025-71144?

CVE-2025-71144 is a context handling vulnerability in the MultiPath TCP (MPTCP) implementation of the Linux kernel.

5

What can happen if CVE-2025-71144 is exploited?

If exploited, CVE-2025-71144 can lead to improper handling of TCP subflows, potentially compromising network communication.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203