{"id":"CVE-2025-68291","title":"mptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().\n\nsyzbot reported divide-by-zero in __tcp_select_window() by\nMPTCP socket. [0]\n…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 9ea05fabce31ff93a0adae8221c58bc6d7b832f3 < 46b8b58f93f1b383c3840fc6e8fab6c3bce9295f","Linux >= 3a13454fd098ed51e733958488f8ec62859a9ed8 < eee39f83246a81d970a9ecb7392b7ab74e660094","Linux >= f6fb2cbc91a81178dea23d463503b4525a76825d < 05f5e26d488cdc7abc2a826cf1071782d5a21203","Linux >= c4f7b0916b95fd2226e5ab98882482b08f52e1c0 < 88163f85d59b4164884df900ee171720fd26686b","Linux >= ae155060247be8dcae3802a95bd1bdf93ab3215d < f07f4ea53e22429c84b20832fa098b5ecc0d4e35","Linux >= 6.1.159 < 6.1.160","Linux >= 6.6.119 < 6.6.120","Linux >= 6.12.60 < 6.12.61","Linux >= 6.17.10 < 6.17.11"],"published":"2025-12-16","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:43:11.466Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-68291","references":[{"url":"https://git.kernel.org/stable/c/46b8b58f93f1b383c3840fc6e8fab6c3bce9295f"},{"url":"https://git.kernel.org/stable/c/eee39f83246a81d970a9ecb7392b7ab74e660094"},{"url":"https://git.kernel.org/stable/c/05f5e26d488cdc7abc2a826cf1071782d5a21203"},{"url":"https://git.kernel.org/stable/c/88163f85d59b4164884df900ee171720fd26686b"},{"url":"https://git.kernel.org/stable/c/f07f4ea53e22429c84b20832fa098b5ecc0d4e35"}],"tags":["cve.org"],"epss":0.00216,"epssPercentile":0.12287,"ingestedAt":"2026-09-08T15:33:26.996Z","slug":"CVE-2025-68291","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: Initialise rcv_mss before calling tcp_send_active_reset() in mptcp_do_fastclose().\n\nsyzbot reported divide-by-zero in __tcp_select_window() by\nMPTCP socket. [0]\n\nWe had a similar issue for the bare TCP and fixed in commit\n499350a5a6e7 (\"tcp: initialize rcv_mss to TCP_MIN_MSS instead\nof 0\").\n\nLet's apply the same fix to mptcp_do_fastclose().\n\n[0]:\nOops: divide error: 0000 [#1] SMP KASAN PTI\nCPU: 0 UID: 0 PID: 6068 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025\nRIP: 0010:__tcp_select_window+0x824/0x1320 net/ipv4/tcp_output.c:3336\nCode: ff ff ff 44 89 f1 d3 e0 89 c1 f7 d1 41 01 cc 41 21 c4 e9 a9 00 00 00 e8 ca 49 01 f8 e9 9c 00 00 00 e8 c0 49 01 f8 44 89 e0 99 <f7> 7c 24 1c 41 29 d4 48 bb 00 00 00 00 00 fc ff df e9 80 00 00 00\nRSP: 0018:ffffc90003017640 EFLAGS: 00010293\nRAX: 0000000000000000 RBX: 0000000000000000 RCX: ffff88807b469e40\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: ffffc90003017730 R08: ffff888033268143 R09: 1ffff1100664d028\nR10: dffffc0000000000 R11: ffffed100664d029 R12: 0000000000000000\nR13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000000\nFS:  000055557faa0500(0000) GS:ffff888126135000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f64a1912ff8 CR3: 0000000072122000 CR4: 00000000003526f0\nCall Trace:\n <TASK>\n tcp_select_window net/ipv4/tcp_output.c:281 [inline]\n __tcp_transmit_skb+0xbc7/0x3aa0 net/ipv4/tcp_output.c:1568\n tcp_transmit_skb net/ipv4/tcp_output.c:1649 [inline]\n tcp_send_active_reset+0x2d1/0x5b0 net/ipv4/tcp_output.c:3836\n mptcp_do_fastclose+0x27e/0x380 net/mptcp/protocol.c:2793\n mptcp_disconnect+0x238/0x710 net/mptcp/protocol.c:3253\n mptcp_sendmsg_fastopen+0x2f8/0x580 net/mptcp/protocol.c:1776\n mptcp_sendmsg+0x1774/0x1980 net/mptcp/protocol.c:1855\n sock_sendmsg_nosec net/socket.c:727 [inline]\n __sock_sendmsg+0xe5/0x270 net/socket.c:742\n __sys_sendto+0x3bd/0x520 net/socket.c:2244\n __do_sys_sendto net/socket.c:2251 [inline]\n __se_sys_sendto net/socket.c:2247 [inline]\n __x64_sys_sendto+0xde/0x100 net/socket.c:2247\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0xfa/0xfa0 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f66e998f749\nCode: ff ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 40 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 a8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffff9acedb8 EFLAGS: 00000246 ORIG_RAX: 000000000000002c\nRAX: ffffffffffffffda RBX: 00007f66e9be5fa0 RCX: 00007f66e998f749\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000003\nRBP: 00007ffff9acee10 R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000001\nR13: 00007f66e9be5fa0 R14: 00007f66e9be5fa0 R15: 0000000000000006\n </TASK>\n\n## Affected\n\n- `Linux >= 9ea05fabce31ff93a0adae8221c58bc6d7b832f3 < 46b8b58f93f1b383c3840fc6e8fab6c3bce9295f`\n- `Linux >= 3a13454fd098ed51e733958488f8ec62859a9ed8 < eee39f83246a81d970a9ecb7392b7ab74e660094`\n- `Linux >= f6fb2cbc91a81178dea23d463503b4525a76825d < 05f5e26d488cdc7abc2a826cf1071782d5a21203`\n- `Linux >= c4f7b0916b95fd2226e5ab98882482b08f52e1c0 < 88163f85d59b4164884df900ee171720fd26686b`\n- `Linux >= ae155060247be8dcae3802a95bd1bdf93ab3215d < f07f4ea53e22429c84b20832fa098b5ecc0d4e35`\n- `Linux >= 6.1.159 < 6.1.160`\n- `Linux >= 6.6.119 < 6.6.120`\n- `Linux >= 6.12.60 < 6.12.61`\n- `Linux >= 6.17.10 < 6.17.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}