---
id: CVE-2026-97522
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mptcp: fix bad accounting in __mptcp_subflow_push_pending()

  If __subflow_push_pending() errors out we should avoid updating the
  copied byte counters, to avoid mismatch…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  mptcp: fix bad accounting in __mptcp_subflow_push_pending()

  If __subflow_push_pending() errors out we should avoid updating the
  copied byte counters, to avoid mismatch…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 0fa1b3783a17d75a4aa1651a18ede041ffca5750 <
    9781fa35d9f7a87a83115acd3a88bc9ce35b5407
  - >-
    Linux >= 0fa1b3783a17d75a4aa1651a18ede041ffca5750 <
    a0a64525f3414268ed4b1945a1dc690aa974dd4f
  - >-
    Linux >= 0fa1b3783a17d75a4aa1651a18ede041ffca5750 <
    dc054821e639a2e14f1419436612db70b6af45fc
  - >-
    Linux >= 0fa1b3783a17d75a4aa1651a18ede041ffca5750 <
    f3ef03357396d4b147d8e76c75fb612c2f264ffc
  - Linux 6.6
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T11:17:02.297'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-97522'
references:
  - url: 'https://git.kernel.org/stable/c/9781fa35d9f7a87a83115acd3a88bc9ce35b5407'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a0a64525f3414268ed4b1945a1dc690aa974dd4f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dc054821e639a2e14f1419436612db70b6af45fc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f3ef03357396d4b147d8e76c75fb612c2f264ffc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T11:06:38.927Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

mptcp: fix bad accounting in __mptcp_subflow_push_pending()

If __subflow_push_pending() errors out we should avoid updating the
copied byte counters, to avoid mismatch push call later on.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
