You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2025 23145
About this tag
CVE-2025-23145 is a Linux kernel vulnerability involving a NULL-pointer dereference in the Multipath TCP (MPTCP) code that can cause kernel panics and availability outages on systems with MPTCP support. A patch has been released to fix this bug. Microsoft has attested that Azure Linux includes the affected open-source library and is potentially impacted, but other Microsoft-distributed kernel artifacts may also be affected depending on their build configuration. This tag covers discussions about the vulnerability, its impact, and the patch for CVE-2025-23145.
The Linux kernel patch for CVE-2025-23145 fixes a subtle but real NULL-pointer dereference in the Multipath TCP (MPTCP) code — a bug that can cause kernel panics and availability outages on systems whose kernels include MPTCP support. Microsoft’s public advisory language that “Azure Linux...