← All Advisories

CVE-2026-97566

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97566

Key Details

CVECVE-2026-97566
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

mptcp: pm: kernel: drop pending ADD_ADDR when removing ID0

The in-kernel MPTCP path manager can leave a stale ADD_ADDR announcement

entry alive when removing the id 0 endpoint. This happens because the id 0

removal path does not tear down pending announcements, unlike the non-zero

id path.

When the PM later reselects id 0 after adding another signal endpoint, it

finds the stale anno_list entry and hits WARN_ON_ONCE(mptcp_pm_is_kernel())

in mptcp_pm_announced_alloc().

Root cause: asymmetry between removal paths.

- Non-zero id path: mptcp_nl_remove_subflow_and_signal_addr() calls

mptcp_pm_remove_announced() to clean up.

- Id 0 path: mptcp_nl_remove_id_zero_address() skips cleanup entirely.

Fix by making the id 0 path symmetric: call mptcp_pm_announced_remove()

and decrement add_addr_signaled before queuing the RM_ADDR.

Subtle detail: signal endpoints are stored in anno_list with port 0, but

msk_local carries the connection's local port. In other words, entries

linked to ID0 paths should have port == 0. A follow-up patch will ensure

that. mptcp_pm_announced_remove() uses use_port=true for comparison. So

clear the port before the lookup. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97566
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97566