PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97522 Linux CVE debrief

A vulnerability in the Linux kernel's mptcp subsystem has been addressed. The issue, resolved in a recent commit, involves improper accounting in the __mptcp_subflow_push_pending function, which could lead to mismatched push calls if __subflow_push_pending errors out. This vulnerability affects Linux kernel deployments and requires verification of patched versions to prevent potential issues. Linux kernel maintainers and users should assess exposure and verify patched versions to ensure proper accounting and prevent mismatched push calls.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Linux kernel maintainers, users, and deployers should assess exposure and verify patched versions to ensure proper accounting and prevent mismatched push calls. Linux kernel deployments require verification of patched versions to prevent potential issues. This vulnerability affects Linux kernel maintainers, users, and deployers who need to verify patched versions and assess exposure.

Why it matters

A vulnerability in the Linux kernel's mptcp subsystem has been addressed. The issue involves improper accounting in the __mptcp_subflow_push_pending function. Linux kernel maintainers and users should assess exposure and verify patched versions to prevent potential issues.

  • Verify patched Linux kernel versions to prevent potential mismatched push calls
  • Assess exposure in Linux kernel deployments to ensure proper accounting

Technical summary

The Linux kernel's mptcp subsystem has a vulnerability in the __mptcp_subflow_push_pending function. If __subflow_push_pending errors out, the function should avoid updating copied byte counters to prevent mismatched push calls. This vulnerability affects Linux kernel deployments and requires verification of patched versions to ensure proper accounting and prevent mismatched push calls. Linux kernel maintainers and users should assess exposure and verify patched versions to prevent potential issues. The vulnerability involves improper accounting, which could lead to mismatched push calls.

Defensive priority

Linux kernel maintainers and users should assess exposure and verify patched versions.

Recommended defensive actions

  • Review Linux kernel versions for patch inclusion
  • Verify __mptcp_subflow_push_pending function updates
  • Assess exposure in Linux kernel deployments
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification of affected versions and exploitation is required. The vulnerability involves improper accounting in the __mptcp_subflow_push_pending function, which could lead to mismatched push calls if __subflow_push_pending errors out. Linux kernel maintainers and users should verify patched versions and assess exposure to ensure proper accounting.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97522 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97522

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97522 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97522

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/9781fa35d9f7a87a83115acd3a88bc9ce35b5407

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a0a64525f3414268ed4b1945a1dc690aa974dd4f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/dc054821e639a2e14f1419436612db70b6af45fc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/f3ef03357396d4b147d8e76c75fb612c2f264ffc

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.