PT-2026-44260 · Linux · Linux Kernel
Published
2026-05-28
·
Updated
2026-05-29
·
CVE-2026-46137
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A data race exists in the Multipath TCP (MPTCP) implementation. The
mptcp pm add timer() helper function, which operates as a timer callback in softirq context, fails to properly hold the socket lock using bh lock sock(). This can lead to synchronization issues when the socket is in use.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel