In the Linux kernel, the following vulnerability has been resolved: mptcp: fix UaF in listener shutdown As reported by Christoph after having refactored the passive socket initialization, the mptcp listener shutdown path is prone to an UaF issue. BUG: KASAN: use-after-free in _raw_spin_lock_bh+0x73/0xe0 Write of size 4 at addr ffff88810cb23098 by task syz-executor731/1266 CPU: 1 PID: 1266 Comm: syz-executor731 Not tainted 6.2.0-rc59af4eaa31c1f6c00c8f1e448ed99a45c66340dd5 #6 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014 Call Trace: <TASK> dump_stack_lvl+0x6e/0x91 print_report+0x16a/0x46f kasan_report+0xad/0x130 kasan_check_range+0x14a/0x1a0 _raw_spin_lock_bh+0x73/0xe0 subflow_error_report+0x6d/0x110 sk_error_report+0x3b/0x190 tcp_disconnect+0x138c/0x1aa0 inet_child_forget+0x6f/0x2e0 inet_csk_listen_stop+0x209/0x1060 __mptcp_close_ssk+0x52d/0x610 mptcp_destroy_common+0x165/0x640 mptcp_destroy+0x13/0x80 __mptcp_destroy_sock+0xe7/0x270 __mptcp_close+0x70e/0x9b0 mptcp_close+0x2b/0x150 inet_release+0xe9/0x1f0 __sock_release+0xd2/0x280 sock_close+0x15/0x20 __fput+0x252/0xa20 task_work_run+0x169/0x250 exit_to_user_mode_prepare+0x113/0x120 syscall_exit_to_user_mode+0x1d/0x40 do_syscall_64+0x48/0x90 entry_SYSCALL_64_after_hwframe+0x72/0xdc The msk grace period can legitly expire in between the last reference count dropped in mptcp_subflow_queue_clean() and the later eventual access in inet_csk_listen_stop() After the previous patch we don't need anymore special-casing msk listener socket cleanup: the mptcp worker will process each of the unaccepted msk sockets. Just drop the now unnecessary code. Please note this commit depends on the two parent ones: mptcp: refactor passive socket initialization mptcp: use the workqueue to destroy unaccepted sockets
Conclusion & alert: CVE-2023-53088 is rated Low Risk (33.3/100): CVSS High severity, with low exploitation likelihood (EPSS 0.16%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.04% | 0.16% | +0.12% |
| 2 | 2026-06-12 | 0.05% | 0.04% | -0.01% |
| 3 | 2026-02-26 | — | 0.05% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2023-53088 unimportant priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2023-53088 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-53088 |
suse
|
medium | CVE-2023-53088 severity moderate: SUSE including 75 source package names (bpftool-4.18.0-553.el8_10, bpftool-7.2.0-362.8.1.el9_3, …), 313 product×package rows across 53 product lines (SLES-LTSS-TERADATA 15 SP2, SUSE Liberty Linux 8, … (53 product lines)): Known Not Affected 264, Fixed 49. | https://www.suse.com/security/cve/CVE-2023-53088/ |
ubuntu
|
medium | CVE-2023-53088 medium priority: Ubuntu including 144 source packages (linux, linux-allwinner-5.19, …), 1285 status rows across 9 suites (bionic, focal, jammy, noble, oracular, plucky, trusty, upstream, xenial): DNE 921, ignored 146, not-affected 140, released 78. | https://ubuntu.com/security/CVE-2023-53088 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| linux | linux_kernel | >= 5.18.10, < 5.19 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 5.19.1, < 6.1.22 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | >= 6.2, < 6.2.8 | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
| linux | linux_kernel | 5.19 | cpe:2.3:o:linux:linux_kernel:5.19:-:*:*:*:*:*:* |
| linux | linux_kernel | 5.19 | cpe:2.3:o:linux:linux_kernel:5.19:rc5:*:*:*:*:*:* |
| linux | linux_kernel | 5.19 | cpe:2.3:o:linux:linux_kernel:5.19:rc6:*:*:*:*:*:* |
| linux | linux_kernel | 5.19 | cpe:2.3:o:linux:linux_kernel:5.19:rc7:*:*:*:*:*:* |
| linux | linux_kernel | 5.19 | cpe:2.3:o:linux:linux_kernel:5.19:rc8:*:*:*:*:*:* |
| linux | linux_kernel | 6.3 | cpe:2.3:o:linux:linux_kernel:6.3:rc1:*:*:*:*:*:* |
| linux | linux_kernel | 6.3 | cpe:2.3:o:linux:linux_kernel:6.3:rc2:*:*:*:*:*:* |