PatchSiren cyber security CVE debrief
CVE-2026-97522 Linux CVE debrief
A vulnerability in the Linux kernel's mptcp subsystem has been addressed. The issue, resolved in a recent commit, involves improper accounting in the __mptcp_subflow_push_pending function, which could lead to mismatched push calls if __subflow_push_pending errors out. This vulnerability affects Linux kernel deployments and requires verification of patched versions to prevent potential issues. Linux kernel maintainers and users should assess exposure and verify patched versions to ensure proper accounting and prevent mismatched push calls.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel maintainers, users, and deployers should assess exposure and verify patched versions to ensure proper accounting and prevent mismatched push calls. Linux kernel deployments require verification of patched versions to prevent potential issues. This vulnerability affects Linux kernel maintainers, users, and deployers who need to verify patched versions and assess exposure.
Why it matters
A vulnerability in the Linux kernel's mptcp subsystem has been addressed. The issue involves improper accounting in the __mptcp_subflow_push_pending function. Linux kernel maintainers and users should assess exposure and verify patched versions to prevent potential issues.
- Verify patched Linux kernel versions to prevent potential mismatched push calls
- Assess exposure in Linux kernel deployments to ensure proper accounting
Technical summary
The Linux kernel's mptcp subsystem has a vulnerability in the __mptcp_subflow_push_pending function. If __subflow_push_pending errors out, the function should avoid updating copied byte counters to prevent mismatched push calls. This vulnerability affects Linux kernel deployments and requires verification of patched versions to ensure proper accounting and prevent mismatched push calls. Linux kernel maintainers and users should assess exposure and verify patched versions to prevent potential issues. The vulnerability involves improper accounting, which could lead to mismatched push calls.
Defensive priority
Linux kernel maintainers and users should assess exposure and verify patched versions.
Recommended defensive actions
- Review Linux kernel versions for patch inclusion
- Verify __mptcp_subflow_push_pending function updates
- Assess exposure in Linux kernel deployments
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification of affected versions and exploitation is required. The vulnerability involves improper accounting in the __mptcp_subflow_push_pending function, which could lead to mismatched push calls if __subflow_push_pending errors out. Linux kernel maintainers and users should verify patched versions and assess exposure to ensure proper accounting.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97522 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97522
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97522 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97522
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/9781fa35d9f7a87a83115acd3a88bc9ce35b5407
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a0a64525f3414268ed4b1945a1dc690aa974dd4f
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/dc054821e639a2e14f1419436612db70b6af45fc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/f3ef03357396d4b147d8e76c75fb612c2f264ffc
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.