CVE-2025-71088
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-71088 is a race condition vulnerability in the Linux kernel's MPTCP (Multipath TCP) subsystem that allows a local low-privileged attacker to trigger kernel assertion failures, resulting in a denial of service. The flaw was published on January 13, 2026, and affects Linux kernel versions 6.1.110–6.1.159, 6.2.1–6.6.119, 6.7–6.12.64, 6.13–6.18.3, and 6.19-rc1 through rc8, as well as Microsoft Azure Linux 3 kernel 6.6.119.3-3. It carries a CVSS v3.1 base score of 5.5 (Medium) (Feedly, Microsoft MSRC).

Technical details

The root cause is a race condition (CWE-362) in the MPTCP subflow handling during simultaneous TCP connection attempts. When a TCP subflow processes a simultaneous-connect SYN-ACK packet after transitioning to the TCP_FIN1 state, the sk_state_change() callback is not invoked for that state transition, allowing the MPTCP fallback check to be bypassed. This leaves the MPTCP socket in an inconsistent state, which subsequently triggers a kernel WARNING at net/mptcp/subflow.c:1515 in the subflow_data_ready function when incoming data is processed. The vulnerability was originally identified via Syzkaller fuzzing, which reproduced the race leading to the inconsistent fallback status (Feedly).

Impact

Successful exploitation causes kernel instability and a denial of service on systems with MPTCP functionality enabled. An attacker with local access and low privileges can trigger kernel WARNING/BUG conditions, potentially crashing or destabilizing the affected system. There is no impact on confidentiality or integrity; the vulnerability is limited to availability (Feedly).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of writing. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.018%, reflecting a very low probability of exploitation in the near term (Feedly).

Mitigation and workarounds

Patches are available in the upstream Linux kernel. Administrators should upgrade to the following fixed versions depending on their current branch: 6.1.160 or later, 6.6.120 or later, 6.12.65 or later, or 6.18.4 or later. Five upstream commits address the issue: 25f1ae942c09, 71154bbe4942, 79f80a7a4784, b5f46a082692, and c9bf31522828. Microsoft released updates for Azure Linux 3 on January 15, 2026. As a temporary workaround, restrict local system access to trusted users only, since the vulnerability requires local privileges to exploit (Feedly, Microsoft MSRC). Ubuntu security notices USN-8277-1, USN-8277-2, USN-8310-1, and USN-8374-1 also address this issue for Ubuntu users (Ubuntu USN-8277-1, Ubuntu USN-8374-1).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.162-1

Fixed

sid

linux: 6.18.5-1

Fixed

trixie

linux: 6.12.69-1

Fixed

Ubuntu

Fixed

bionic

linux

Not Affected

bionic (esm-infra)

linux

Not Affected

bionic (fips-updates)

linux-fips

Not Affected

bionic (fips)

linux-fips

Not Affected

devel

linux

Not Affected

focal

linux

Not Affected

focal (esm-infra)

linux

Not Affected

focal (fips-updates)

linux-fips

Not Affected

RHEL / CentOS

Affected

RHEL 8

Not Affected

RHEL 9

kernel-rt.src

Affected

RHEL 10

kernel.src

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-80904MEDIUM5.9
  • Linux Kernel logoLinux Kernel
  • linux-oracle-7.0
NoYesSep 04, 2026
CVE-2026-80905MEDIUM5.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.8
NoYesSep 04, 2026
CVE-2026-80913MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-intel-iotg
NoYesSep 04, 2026
CVE-2026-80912MEDIUM4.4
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency-hwe-5.15
NoYesSep 04, 2026
CVE-2026-80906NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-4.15
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management