In the Linux kernel, the following vulnerability has been resolved: mptcp: use OPTION_MPTCP_MPJ_SYNACK in subflow_finish_connect() The Linux kernel CVE team has assigned CVE-2024-35840 to this issue. Upstream advisory: https://lore.kernel.org/linux-cve-announce/2024051756-CVE-2024-35840-99fa@gregkh/T
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2281283]
The result of automatic check (that is developed by Alexander Larkin) for this CVE-2024-35840 is: SKIP The Fixes patch not applied yet, so unlikely that actual: f296234c98a8 YES NO YES unknown (where first YES/NO value means if related sources built).
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9315 https://access.redhat.com/errata/RHSA-2024:9315