9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: fix potential data-race
This mptcp_pm_add_timer() helper is executed as a timer callback in
softirq context. To avoid any data races, the socket lock needs to be
held with bh_lock_sock().
If the socket is in use, retry again soon after, similar to what is done
with the keepalive timer.
mptcp: pm: ADD_ADDR rtx: fix potential data-race
This mptcp_pm_add_timer() helper is executed as a timer callback in
softirq context. To avoid any data races, the socket lock needs to be
held with bh_lock_sock().
If the socket is in use, retry again soon after, similar to what is done
with the keepalive timer.
Basic Information
ID
CVE-2026-46137
Source
Linux
Published
May 28, 2026 at 09:35
Modified
May 30, 2026 at 10:48
Affected Product
Vendor
Linux
Product
Linux
Version
00cfd77b9063dcdf3628a7087faba60de85a9cc8
Affected Versions
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 5.10
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 00cfd77b9063dcdf3628a7087faba60de85a9cc8
Linux Linux 5.10
References
- git.kernel.org /stable/c/013dcdc1961543b9a3433466bc8c79a2f4ca75b5
- git.kernel.org /stable/c/6e4710d7d8782cb61af29a7e7111ddfc38b9e1a3
- git.kernel.org /stable/c/2ad56e434199ca24a812bb353667aa1c3860f513
- git.kernel.org /stable/c/cc3c0399361efaaf7ae64262eb3f70829b1189c6
- git.kernel.org /stable/c/5cd6e0ad79d2615264f63929f8b457ad97ae550d