CVE-2025-38491 | Linux Kernel prior 6.12.40/6.15.8 mptcp net/mptcp/protocol.h __mptcp_do_fallback infinite loop (EUVD-2025-22872 / Nessus ID 265749)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.39/6.15.7/6654efe264b014d8ea9fc38f79efb568b1b79069/609937aa962a62e93acfc04dd370b665e6152dfb. This affects the function __mptcp_do_fallback in the library net/mptcp/protocol.h of the component mptcp. The manipulation results in infinite loop.
This vulnerability is identified as CVE-2025-38491. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.