LiveActive security incident?Get immediate response
CVE Record

CVE-2024-36889: mptcp: ensure snd_nxt is properly initialized on connect

In the Linux kernel, the following vulnerability has been resolved: mptcp: ensure snd_nxt is properly initialized on connect Christoph reported a splat hinting at a corrupted snd_una: WARNING: CPU: 1 PID: 38 at net/mptcp/protocol.c:1005 __mptcp_clean_una+0x4b3/0x620 net/mptcp/protocol.c:1005 Modules linked in: CPU: 1 PID: 38 Comm: kworker/1:1 Not tainted 6.9.0-rc1-gbbeac67456c9 #59 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014 Workqueue: events mptcp_worker RIP: 0010:__mptcp_clean_una+0x4b3/0x620 net/mptcp/protocol.c:1005 Code: be 06 01 00 00 bf 06 01 00 00 e8 a8 12 e7 fe e9 00 fe ff ff e8 8e 1a e7 fe 0f b7 ab 3e 02 00 00 e9 d3 fd ff ff e8 7d 1a e7 fe <0f> 0b 4c 8b bb e0 05 00 00 e9 74 fc ff ff e8 6a 1a e7 fe 0f 0b e9 RSP: 0018:ffffc9000013fd48 EFLAGS: 00010293 RAX: 0000000000000000 RBX: ffff8881029bd280 RCX: ffffffff82382fe4 RDX: ffff8881003cbd00 RSI: ffffffff823833c3 RDI: 0000000000000001 RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000 R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888138ba8000 R13: 0000000000000106 R14: ffff8881029bd908 R15: ffff888126560000 FS: 0000000000000000(0000) GS:ffff88813bd00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f604a5dae38 CR3: 0000000101dac002 CR4: 0000000000170ef0 Call Trace: <TASK> __mptcp_clean_una_wakeup net/mptcp/protocol.c:1055 [inline] mptcp_clean_una_wakeup net/mptcp/protocol.c:1062 [inline] __mptcp_retrans+0x7f/0x7e0 net/mptcp/protocol.c:2615 mptcp_worker+0x434/0x740 net/mptcp/protocol.c:2767 process_one_work+0x1e0/0x560 kernel/workqueue.c:3254 process_scheduled_works kernel/workqueue.c:3335 [inline] worker_thread+0x3c7/0x640 kernel/workqueue.c:3416 kthread+0x121/0x170 kernel/kthread.c:388 ret_from_fork+0x44/0x50 arch/x86/kernel/process.c:147 ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:243 </TASK> When fallback to TCP happens early on a client socket, snd_nxt is not yet initialized and any incoming ack will copy such value into snd_una. If the mptcp worker (dumbly) tries mptcp-level re-injection after such ack, that would unconditionally trigger a send buffer cleanup using 'bad' snd_una values. We could easily disable re-injection for fallback sockets, but such dumb behavior already helped catching a few subtle issues and a very low to zero impact in practice. Instead address the issue always initializing snd_nxt (and write_seq, for consistency) at connect time.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysislow

Security readout for executives and security teams

Plain-English summary

This is a Linux kernel MPTCP bug where a connection fallback path can leave sequence tracking uninitialized. Under specific timing, later acknowledgement handling can use bad internal values and trigger a kernel warning or cleanup path. The source describes very low to zero practical impact, but patched kernels should still be adopted through normal maintenance.

Executive priority

Handle through standard kernel patch management unless your environment heavily depends on MPTCP or shows related instability. There is no source-backed evidence of active exploitation, but delaying kernel fixes increases cumulative operational risk.

Technical view

In MPTCP client sockets, early fallback to TCP can occur before snd_nxt is initialized. An incoming ACK can propagate that value into snd_una, and mptcp_worker reinjection may then invoke send-buffer cleanup with corrupted accounting. The upstream fix initializes snd_nxt and write_seq during connect.

Likely exposure

Exposure is limited to Linux systems using affected kernel code with MPTCP enabled or reachable in client connection paths. Exact exposure depends on kernel branch, distribution backports, and whether vendor fixes from the referenced stable commits are present.

Exploitation context

The provided sources do not show active exploitation, and KEV status is false. The report is based on a kernel warning observed in a QEMU test environment. No public exploit details are provided in the bundle.

Researcher notes

The affected-version data in the bundle is uneven, listing both upstream commits and version values. Treat upstream commits as fix references and confirm actual distro impact through vendor advisories. The bug appears reliability-oriented, with no cited privilege escalation or data exposure path.

Mitigation direction

  • Update Linux kernels to vendor releases containing the referenced stable fixes.
  • Review Debian LTS guidance if running Debian-based affected systems.
  • Confirm distribution backports rather than relying only on upstream version numbers.
  • If patching is delayed, check vendor guidance for supported operational workarounds.

Validation and detection

  • Inventory Linux kernel versions and distribution patch levels across affected hosts.
  • Check whether MPTCP is enabled or used in relevant environments.
  • Verify vendor changelogs include the CVE or referenced stable commits.
  • Monitor kernel logs for MPTCP warnings or unexpected connection instability.
Prepared
Confidence
medium
Sources
9

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-36889 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
8Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux8fd738049ac3d67a937d36577763b47180aae1ad, 8fd738049ac3d67a937d36577763b47180aae1ad, 8fd738049ac3d67a937d36577763b47180aae1ad, 8fd738049ac3d67a937d36577763b47180aae1ad, 8fd738049ac3d67a937d36577763b47180aae1ad, 8fd738049ac3d67a937d36577763b47180aae1adunaffected
LinuxLinux5.9, 0, 5.10.218, 5.15.159, 6.1.91, 6.6.31, 6.8.10, 6.9affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.