Use of Uninitialized Variable in Linux kernel - CVE-2026-89554
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt the path manager's id-based subflow bookkeeping.
The vulnerability exists due to use of an uninitialized local_id field in mptcp_token_join_cookie_init_state() when reconstructing MP_JOIN request sockets for fourth acknowledgments under SYN cookies. A remote attacker can send concurrent MP_JOIN SYNs to influence the stale address ID and corrupt the path manager's id-based subflow bookkeeping.