OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97523

HIGH · CVSS 7.5 EPSS 0.67%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's mptcp scheduler, where a race condition between the scheduler and subflow socket state changes can lead to data transmission failures. This issue may result in a divide-by-zero error during socket release operations, potentially causing system instability. Organizations using affected Linux kernel versions with mptcp enabled should prioritize addressing this vulnerability to ensure reliable data transmission and prevent potential crashes.

CVE
CVE-2026-97523
Severity
HIGH
CVSS
7.5
EPSS
0.67%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state change The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation. Address the issue by explicitly checking for the critical scenario.