CVE-2026-46168
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/05/2026
Last modified:
10/06/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
mptcp: fix scheduling with atomic in timestamp sockopt<br />
<br />
Using lock_sock_fast() (atomic context) around sock_set_timestamp()<br />
and sock_set_timestamping() is unsafe, as both helpers can sleep.<br />
<br />
Replace lock_sock_fast() with sleepable lock_sock()/release_sock()<br />
to avoid scheduling while atomic panic.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.14 (including) | 5.15.209 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 5.16 (including) | 6.1.175 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.2 (including) | 6.6.140 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.7 (including) | 6.12.88 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.13 (including) | 6.18.30 (excluding) |
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 6.19 (including) | 7.0.7 (excluding) |
| cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0949d8bbbedbafe0136a1723c41eb823c2f1e09d
- https://git.kernel.org/stable/c/7eb513b42721bee4b96da69f6188d5a7783f210d
- https://git.kernel.org/stable/c/8a005fe451c73fd2b3d1faa5643c11e6bd07acfc
- https://git.kernel.org/stable/c/b157dab93a7af44a84e78cf0cb311dde475cff5b
- https://git.kernel.org/stable/c/b5c52908d52c6c8eb8933264aa6087a0600fd892
- https://git.kernel.org/stable/c/e792cfb6aeaf65612cdf8e3ac431d65e66283654
- https://git.kernel.org/stable/c/ebeb70e29e37cfce899309cc2665a3bfe960ed94



