[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-DEBIAN-CVE-2025-71088":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-15T22:50:23.791Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":16,"duplicates":23,"related":24,"reserved_at":9,"published_at":25,"modified_at":26,"state":9,"summary":27,"references_raw":29,"kevs":36,"epss":9,"epss_history":37,"metrics":38,"affected":45},"DEBIAN-CVE-2025-71088","In the Linux kernel, the following vulnerability has been resolved:  mptcp: fallback earlier on simult connection  Syzkaller reports a simult-connect race leading to inconsistent fallback status:    WARNING: CPU: 3 PID: 33 at net/mptcp/subflow.c:1515 subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515   Modules linked in:   CPU: 3 UID: 0 PID: 33 Comm: ksoftirqd/3 Not tainted syzkaller #0 PREEMPT(full)   Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014   RIP: 0010:subflow_data_ready+0x40b/0x7c0 net/mptcp/subflow.c:1515   Code: 89 ee e8 78 61 3c f6 40 84 ed 75 21 e8 8e 66 3c f6 44 89 fe bf 07 00 00 00 e8 c1 61 3c f6 41 83 ff 07 74 09 e8 76 66 3c f6 90 \u003C0f> 0b 90 e8 6d 66 3c f6 48 89 df e8 e5 ad ff ff 31 ff 89 c5 89 c6   RSP: 0018:ffffc900006cf338 EFLAGS: 00010246   RAX: 0000000000000000 RBX: ffff888031acd100 RCX: ffffffff8b7f2abf   RDX: ffff88801e6ea440 RSI: ffffffff8b7f2aca RDI: 0000000000000005   RBP: 0000000000000000 R08: 0000000000000005 R09: 0000000000000007   R10: 0000000000000004 R11: 0000000000002c10 R12: ffff88802ba69900   R13: 1ffff920000d9e67 R14: ffff888046f81800 R15: 0000000000000004   FS:  0000000000000000(0000) GS:ffff8880d69bc000(0000) knlGS:0000000000000000   CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033   CR2: 0000560fc0ca1670 CR3: 0000000032c3a000 CR4: 0000000000352ef0   Call Trace:    \u003CTASK>    tcp_data_queue+0x13b0/0x4f90 net/ipv4/tcp_input.c:5197    tcp_rcv_state_process+0xfdf/0x4ec0 net/ipv4/tcp_input.c:6922    tcp_v6_do_rcv+0x492/0x1740 net/ipv6/tcp_ipv6.c:1672    tcp_v6_rcv+0x2976/0x41e0 net/ipv6/tcp_ipv6.c:1918    ip6_protocol_deliver_rcu+0x188/0x1520 net/ipv6/ip6_input.c:438    ip6_input_finish+0x1e4/0x4b0 net/ipv6/ip6_input.c:489    NF_HOOK include/linux/netfilter.h:318 [inline]    NF_HOOK include/linux/netfilter.h:312 [inline]    ip6_input+0x105/0x2f0 net/ipv6/ip6_input.c:500    dst_input include/net/dst.h:471 [inline]    ip6_rcv_finish net/ipv6/ip6_input.c:79 [inline]    NF_HOOK include/linux/netfilter.h:318 [inline]    NF_HOOK include/linux/netfilter.h:312 [inline]    ipv6_rcv+0x264/0x650 net/ipv6/ip6_input.c:311    __netif_receive_skb_one_core+0x12d/0x1e0 net/core/dev.c:5979    __netif_receive_skb+0x1d/0x160 net/core/dev.c:6092    process_backlog+0x442/0x15e0 net/core/dev.c:6444    __napi_poll.constprop.0+0xba/0x550 net/core/dev.c:7494    napi_poll net/core/dev.c:7557 [inline]    net_rx_action+0xa9f/0xfe0 net/core/dev.c:7684    handle_softirqs+0x216/0x8e0 kernel/softirq.c:579    run_ksoftirqd kernel/softirq.c:968 [inline]    run_ksoftirqd+0x3a/0x60 kernel/softirq.c:960    smpboot_thread_fn+0x3f7/0xae0 kernel/smpboot.c:160    kthread+0x3c2/0x780 kernel/kthread.c:463    ret_from_fork+0x5d7/0x6f0 arch/x86/kernel/process.c:148    ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245    \u003C/TASK>  The TCP subflow can process the simult-connect syn-ack packet after transitioning to TCP_FIN1 state, bypassing the MPTCP fallback check, as the sk_state_change() callback is not invoked for * -> FIN_WAIT1 transitions.  That will move the msk socket to an inconsistent status and the next incoming data will hit the reported splat.  Close the race moving the simult-fallback check at the earliest possible stage - that is at syn-ack generation time.  About the fixes tags: [2] was supposed to also fix this issue introduced by [3]. [1] is required as a dependence: it was not explicitly marked as a fix, but it is one and it has already been backported before [3]. In other words, this commit should be backported up to [3], including [2] and [1] if that's not already there.",null,[],[],[],[14],{"_key":15},"CVE-2025-71088",[17,19,21],{"_key":18},"DLA-4476-1",{"_key":20},"DSA-6126-1",{"_key":22},"DSA-6127-1",[],[],"2026-01-13T16:16:08.460Z","2026-06-15T19:06:00.708466959Z",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[30],{"url":31,"sources":32,"tags":34},"https://security-tracker.debian.org/tracker/CVE-2025-71088",[33],"osv_debian",[35],"Advisory",[],[],[39],{"source":33,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":40,"cvss_v4_0":9},{"baseScore":41,"baseSeverity":9,"vectorString":42,"impactScore":43,"exploitabilityScore":44},5.5,"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",6,4.6,[46,67],{"ecosystem":47,"name":48,"vendor":49,"product":48,"cpe_part":9,"purl_type":50,"purl_namespace":49,"purl_name":48,"source":9,"versions":51},"Debian","linux","debian","deb",[52,56,57,61,64],{"version":53,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",true,"ecosystem",{"version":53,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":58,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":59,"version_end_type":60,"fixed_in":9},"lt6_1_162_1","6.1.162-1","excluding",{"version":62,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":63,"version_end_type":60,"fixed_in":9},"lt6_12_69_1","6.12.69-1",{"version":65,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":66,"version_end_type":60,"fixed_in":9},"lt6_18_5_1","6.18.5-1",{"ecosystem":47,"name":68,"vendor":49,"product":68,"cpe_part":9,"purl_type":50,"purl_namespace":49,"purl_name":68,"source":9,"versions":69},"linux-6.1",[70,71],{"version":53,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":72,"is_range":54,"range_type":55,"version_start":9,"version_start_type":9,"version_end":73,"version_end_type":60,"fixed_in":9},"lt6_1_162_1~deb11u1","6.1.162-1~deb11u1"]