CVE-2025-38491 | Linux Kernel prior 6.12.40/6.15.8 mptcp net/mptcp/protocol.h __mptcp_do_fallback infinite loop
A vulnerability was found in Linux Kernel up to 6.12.39/6.15.7/6654efe264b014d8ea9fc38f79efb568b1b79069/609937aa962a62e93acfc04dd370b665e6152dfb. It has been declared as critical. Affected by this vulnerability is the function __mptcp_do_fallback in the library net/mptcp/protocol.h of the component mptcp. The manipulation leads to infinite loop.
This vulnerability is known as CVE-2025-38491. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.