Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-35894

22
FAUCET Score

CVE-2024-35894 is a high-severity vulnerability in the Linux kernel's Multipath TCP (MPTCP) implementation, allowing BPF programs to improperly access MPTCP-level proto_ops from a TCP subflow socket. This flaw can lead to a denial of service (DoS) or potentially privilege escalation, as indicated by its CVSS score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). While the vulnerability has a high potential impact, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.7, < 6.8.5CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.9:rc1:*:*:*:*:*:*
6.9CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.9:rc2:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.22%
Probability of exploitation in next 30 days
EPSS Percentile
12.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0022 is in the 42nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-503.11.1.el9_5
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2024-35894Low

kernel: mptcp: prevent BPF accessing lowat from a subflow socket.

May 19, 2024

References

git.kernel.org / stable/c/3ffb1ab698376f09cc33101c07c1be229389fe29
Patch
git.kernel.org / stable/c/ee3c845787b621cfe82c2e52c513024a9d7a78f5
Patch
git.kernel.org / stable/c/fcf4692fa39e86a590c14a4af2de704e1d20a3b5
Patch
security.netapp.com / advisory/ntap-20250321-0002