{"id":"DEBIAN-CVE-2024-36889","details":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: ensure snd_nxt is properly initialized on connect  Christoph reported a splat hinting at a corrupted snd_una:    WARNING: CPU: 1 PID: 38 at net/mptcp/protocol.c:1005 __mptcp_clean_una+0x4b3/0x620 net/mptcp/protocol.c:1005   Modules linked in:   CPU: 1 PID: 38 Comm: kworker/1:1 Not tainted 6.9.0-rc1-gbbeac67456c9 #59   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.11.0-2.el7 04/01/2014   Workqueue: events mptcp_worker   RIP: 0010:__mptcp_clean_una+0x4b3/0x620 net/mptcp/protocol.c:1005   Code: be 06 01 00 00 bf 06 01 00 00 e8 a8 12 e7 fe e9 00 fe ff ff e8   \t8e 1a e7 fe 0f b7 ab 3e 02 00 00 e9 d3 fd ff ff e8 7d 1a e7 fe   \t\u003c0f\u003e 0b 4c 8b bb e0 05 00 00 e9 74 fc ff ff e8 6a 1a e7 fe 0f 0b e9   RSP: 0018:ffffc9000013fd48 EFLAGS: 00010293   RAX: 0000000000000000 RBX: ffff8881029bd280 RCX: ffffffff82382fe4   RDX: ffff8881003cbd00 RSI: ffffffff823833c3 RDI: 0000000000000001   RBP: 0000000000000000 R08: 0000000000000001 R09: 0000000000000000   R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888138ba8000   R13: 0000000000000106 R14: ffff8881029bd908 R15: ffff888126560000   FS:  0000000000000000(0000) GS:ffff88813bd00000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 00007f604a5dae38 CR3: 0000000101dac002 CR4: 0000000000170ef0   Call Trace:    \u003cTASK\u003e    __mptcp_clean_una_wakeup net/mptcp/protocol.c:1055 [inline]    mptcp_clean_una_wakeup net/mptcp/protocol.c:1062 [inline]    __mptcp_retrans+0x7f/0x7e0 net/mptcp/protocol.c:2615    mptcp_worker+0x434/0x740 net/mptcp/protocol.c:2767    process_one_work+0x1e0/0x560 kernel/workqueue.c:3254    process_scheduled_works kernel/workqueue.c:3335 [inline]    worker_thread+0x3c7/0x640 kernel/workqueue.c:3416    kthread+0x121/0x170 kernel/kthread.c:388    ret_from_fork+0x44/0x50 arch/x86/kernel/process.c:147    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:243    \u003c/TASK\u003e  When fallback to TCP happens early on a client socket, snd_nxt is not yet initialized and any incoming ack will copy such value into snd_una. If the mptcp worker (dumbly) tries mptcp-level re-injection after such ack, that would unconditionally trigger a send buffer cleanup using 'bad' snd_una values.  We could easily disable re-injection for fallback sockets, but such dumb behavior already helped catching a few subtle issues and a very low to zero impact in practice.  Instead address the issue always initializing snd_nxt (and write_seq, for consistency) at connect time.","modified":"2026-09-15T09:03:08.544841177Z","published":"2024-05-30T16:15:12.410Z","upstream":["CVE-2024-36889"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-36889"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.94-1"}]}],"versions":["6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1~bpo11+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36889.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36889.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.8.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-36889.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}