CVE-2026-45889

Description

A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. This vulnerability occurs due to incorrect accounting for out-of-order (OoO) data in the mptcp_rcvbuf_grow() function. A subtle and very unlikely race condition could lead to a divide-by-zero error, potentially causing a system crash (Denial of Service).

Understanding the Weakness (CWE)

Availability

Technical Impact: DoS: Crash, Exit, or Restart

A Divide by Zero results in a crash.

Frequently Asked Questions

Want to get errata notifications? Sign up here.