---
cve: "CVE-2024-35840"
severity: "LOW"
cvss: 3.1
epss: "22%"
vendor: "Linux"
kev: false
exploited: false
published: "2024-05-17 15:15:21"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T14:36:48+02:00"
---

# CVE-2024-35840

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect()

subflow_finish_connect() uses four fields (backup, join_id, thmac, none)
that may contain garbage unless OPTION_MPTCP_MPJ_SYNACK has been set
in mptcp_parse_option()

## Patch verfügbar (OSV)

- Kernel ≥ 5.15.148
- Kernel ≥ 6.1.75
- Kernel ≥ 6.6.14
- Kernel ≥ 6.7.2

## Referenzen

- <https://git.kernel.org/stable/c/413b913507326972135d2977975dbff8b7f2c453>
- <https://git.kernel.org/stable/c/51e4cb032d49ce094605f27e45eabebc0408893c>
- <https://git.kernel.org/stable/c/ad3e8f5c3d5c53841046ef7a947c04ad45a20721>
- <https://git.kernel.org/stable/c/76e8de7273a22a00d27e9b8b7d4d043d6433416a>
- <https://git.kernel.org/stable/c/be1d9d9d38da922bd4beeec5b6dd821ff5a1dfeb>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-35840) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
