CVE-2024-35840

Source
https://cve.org/CVERecord?id=CVE-2024-35840
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35840.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-35840
Downstream
Related
Published
2024-05-17T14:27:31.166Z
Modified
2026-05-28T03:52:47.941184689Z
Summary
mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect()
Details

In the Linux kernel, the following vulnerability has been resolved:

mptcp: use OPTIONMPTCPMPJSYNACK in subflowfinish_connect()

subflowfinishconnect() uses four fields (backup, joinid, thmac, none) that may contain garbage unless OPTIONMPTCPMPJSYNACK has been set in mptcpparseoption()

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35840.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f296234c98a8fcec94eec80304a873f635d350ea
Fixed
413b913507326972135d2977975dbff8b7f2c453
Fixed
51e4cb032d49ce094605f27e45eabebc0408893c
Fixed
ad3e8f5c3d5c53841046ef7a947c04ad45a20721
Fixed
76e8de7273a22a00d27e9b8b7d4d043d6433416a
Fixed
be1d9d9d38da922bd4beeec5b6dd821ff5a1dfeb

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35840.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
5.15.148
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.75
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.14
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.7.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-35840.json"