CVE-2025-23145 | Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2 mptcp /net/mptcp/subflow.c subflow_hmac_valid null pointer dereference (Nessus ID 237088 / WID-SEC-2025-0922)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.1.134/6.6.87/6.12.23/6.13.11/6.14.2. Affected by this vulnerability is the function subflow_hmac_valid of the file /net/mptcp/subflow.c of the component mptcp. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2025-23145. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.