Security readout for executives and security teams
Plain-English summary
A flaw in Linux’s Multipath TCP handling can leave internal option state uninitialized and then use it while processing network traffic. The supplied rating is critical, but the bundle documents a sanitizer-detected kernel bug—not demonstrated compromise, data theft, or code execution. Organizations should identify affected kernels and apply vendor-provided updates promptly.
Executive priority
Treat this as an expedited kernel-patching issue, especially on externally reachable or MPTCP-dependent systems. Begin inventory and vendor verification immediately. The critical score supports urgency, but the supplied evidence does not justify declaring an incident or assuming remote compromise without additional indicators.
Technical view
MPTCP cleared its received-suboption bitmask without consistently clearing related per-suboption bitfields. syzbot triggered a KMSAN uninitialized-value report during sequence expansion, ACK-state updating, and incoming-option processing. Linux stable commits consolidate this state. The supplied CVSS is 9.8, although the available description does not establish how confidentiality, integrity, and availability impacts were demonstrated.
Likely exposure
Systems running source-listed affected Linux kernel revisions and processing MPTCP traffic are candidates. Exposure depends on distribution backports and whether MPTCP code is reachable. The supplied version data contains duplicated commit hashes and an ambiguous “0” entry, so confirm exposure through vendor package advisories and fix-commit presence rather than version strings alone.
Exploitation context
The bundle marks this CVE as absent from KEV and cites no active exploitation or public proof of concept. The known evidence is a syzbot-generated KMSAN failure. Network reachability is asserted by the supplied CVSS vector, but practical exploitability and security impact beyond uninitialized-state use are not demonstrated in the provided material.
Researcher notes
The strongest evidence is an uninitialized-value path reported by KMSAN in net/mptcp/options.c and related sequence/ACK handling. No CWE is supplied, and the description is truncated. Researchers should distinguish the confirmed state-initialization defect from the CVSS claim of complete confidentiality, integrity, and availability impact, which is not substantiated here.
Mitigation direction
Apply distribution or product-vendor kernel updates incorporating the cited Linux stable fixes.
Prioritize systems where MPTCP is enabled, reachable, or operationally required.
If updates are unavailable, request product-specific mitigation guidance from the relevant vendor.
Do not assume an unaffected version solely from the kernel release string; account for backports.
Validation and detection
Inventory running kernel packages and determine whether MPTCP functionality is enabled or reachable.
Compare vendor package changelogs against CVE-2025-21707 and the cited stable commits.
Confirm the updated kernel is running after remediation, including following required reboots.
Review kernel and monitoring records for related MPTCP faults or uninitialized-value reports.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21707 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
9Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.