CVE-2026-23169
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/02/2026
Last modified:
14/02/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mptcp: fix race in mptcp_pm_nl_flush_addrs_doit()<br />
<br />
syzbot and Eulgyu Kim reported crashes in mptcp_pm_nl_get_local_id()<br />
and/or mptcp_pm_nl_is_backup()<br />
<br />
Root cause is list_splice_init() in mptcp_pm_nl_flush_addrs_doit()<br />
which is not RCU ready.<br />
<br />
list_splice_init_rcu() can not be called here while holding pernet->lock<br />
spinlock.<br />
<br />
Many thanks to Eulgyu Kim for providing a repro and testing our patches.



