CVE-2026-46158
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/05/2026
Last modified:
09/06/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mptcp: pm: ADD_ADDR rtx: always decrease sk refcount<br />
<br />
When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().<br />
It should then be released in all cases at the end.<br />
<br />
Some (unlikely) checks were returning directly instead of calling<br />
sock_put() to decrease the refcount. Jump to a new &#39;exit&#39; label to call<br />
__sock_put() (which will become sock_put() in the next commit) to fix<br />
this potential leak.<br />
<br />
While at it, drop the &#39;!msk&#39; check which cannot happen because it is<br />
never reset, and explicitly mark the remaining one as "unlikely".
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.10 (including) | 6.6.142 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.92 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.30 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/25e37407442b8766ec2cf52fb4e31b5c3d3aeeae
- https://git.kernel.org/stable/c/9426265e157dd77ec237c795901ed4dea6d69b5c
- https://git.kernel.org/stable/c/9634cb35af17019baec21ca648516ce376fa10e6
- https://git.kernel.org/stable/c/acd3d3562315c99f3c0db16f0fcc5f0306638982
- https://git.kernel.org/stable/c/b41dd76f3b9735096c21d3e799a2b9fe36498d57



