PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97523 Linux CVE debrief

A race condition vulnerability in the Linux kernel's mptcp scheduler has been resolved. The issue arises from a potential race between the scheduler and subflow sockets state change, which could lead to failed data transmission and a later release attempting to use a reset mss_now value of 0 for a divide operation. This vulnerability affects Linux kernel maintainers and users, who should assess exposure and prioritize verification of affected systems. The CVE record and NVD entry provide limited information about the vulnerability.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Linux kernel maintainers, Linux system administrators, and security teams responsible for Linux systems. They should assess exposure and prioritize verification of affected systems. Linux kernel configurations and versions should be reviewed to determine potential exposure. System logs should be verified for signs of exploitation. Patches or updates provided by the Linux kernel maintainers should be applied.

Why it matters

A race condition vulnerability in the Linux kernel's mptcp scheduler has been resolved. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.

  • Verify Linux kernel configurations and versions to determine potential exposure
  • Monitor system logs for signs of exploitation
  • Prioritize patching or updating Linux kernel to prevent potential issues

Technical summary

The Linux kernel's mptcp scheduler has a race condition vulnerability that could lead to failed data transmission and a later release attempting to use a reset mss_now value of 0 for a divide operation. This vulnerability affects Linux kernel maintainers and users, who should assess exposure and prioritize verification of affected systems. The issue arises from a potential race between the scheduler and subflow sockets state change. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.

Defensive priority

Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems.

Recommended defensive actions

  • Review Linux kernel configurations and versions to determine potential exposure
  • Verify system logs for signs of exploitation
  • Apply patches or updates provided by the Linux kernel maintainers
  • Monitor system logs for signs of exploitation
  • Prioritize patching or updating Linux kernel to prevent potential issues
  • Verify Linux kernel configurations and versions to determine potential exposure
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected systems and potential impact. Linux kernel maintainers and users should assess exposure and prioritize verification of affected systems. The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail and a later release could try to use mss_now reset to 0 for a divide operation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97523 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97523

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97523 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97523

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/42064de57fb83231fcc89663a94885f228a1ee53

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4c856f3c151a2f3fa237caa651c44015916ca584

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8f11430d51ff8365bc51b670bc3002b65ae4c6b7

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a09c87abf10a0a7e203137c75b5381aa63d9b31d

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.