PatchSiren cyber security CVE debrief
CVE-2026-97523 Linux CVE debrief
A race condition vulnerability in the Linux kernel's mptcp scheduler has been resolved. The issue arises from a potential race between the scheduler and subflow sockets state change, which could lead to failed data transmission and a later release attempting to use a reset mss_now value of 0 for a divide operation. This vulnerability affects Linux kernel maintainers and users, who should assess exposure and prioritize verification of affected systems. The CVE record and NVD entry provide limited information about the vulnerability.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-25
- Original CVE updated
- 2026-09-25
- Advisory published
- 2026-09-25
- Advisory updated
- 2026-09-25
Who should care
Linux kernel maintainers, Linux system administrators, and security teams responsible for Linux systems. They should assess exposure and prioritize verification of affected systems. Linux kernel configurations and versions should be reviewed to determine potential exposure. System logs should be verified for signs of exploitation. Patches or updates provided by the Linux kernel maintainers should be applied.
Why it matters
A race condition vulnerability in the Linux kernel's mptcp scheduler has been resolved. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.
- Verify Linux kernel configurations and versions to determine potential exposure
- Monitor system logs for signs of exploitation
- Prioritize patching or updating Linux kernel to prevent potential issues
Technical summary
The Linux kernel's mptcp scheduler has a race condition vulnerability that could lead to failed data transmission and a later release attempting to use a reset mss_now value of 0 for a divide operation. This vulnerability affects Linux kernel maintainers and users, who should assess exposure and prioritize verification of affected systems. The issue arises from a potential race between the scheduler and subflow sockets state change. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.
Defensive priority
Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.
Recommended defensive actions
- Review Linux kernel configurations and versions to determine potential exposure
- Verify system logs for signs of exploitation
- Apply patches or updates provided by the Linux kernel maintainers
- Monitor system logs for signs of exploitation
- Prioritize patching or updating Linux kernel to prevent potential issues
- Verify Linux kernel configurations and versions to determine potential exposure
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected systems and potential impact. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-97523 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-97523
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-97523 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97523
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/42064de57fb83231fcc89663a94885f228a1ee53
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4c856f3c151a2f3fa237caa651c44015916ca584
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/8f11430d51ff8365bc51b670bc3002b65ae4c6b7
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/a09c87abf10a0a7e203137c75b5381aa63d9b31d
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.