PT-2026-44291 · Opensuse+1 · Opensuse Tumbleweed+1

CVE-2026-46168

·

Published

2026-05-28

·

Updated

2026-07-31

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified) openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description An issue exists in the Multipath TCP (mptcp) implementation where the use of lock sock fast() (an atomic context) around the sock set timestamp() and sock set timestamping() functions is unsafe. This is because both helper functions can sleep, which may lead to a scheduling while atomic panic, a state where the system attempts to switch tasks while holding a lock that forbids sleeping.
Recommendations Replace lock sock fast() with sleepable lock sock() and release sock() functions. Update to kernel-devel-7.0.11-1.1 or a newer version.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-46168
ECHO-B3ED-51D6-9E67
OPENSUSE-SU-2026:10954-1
USN-8566-1
USN-8567-1
USN-8568-1
USN-8569-1
USN-8574-1
USN-8574-2
USN-8574-3
USN-8575-1
USN-8575-2
USN-8575-3
USN-8576-1
USN-8576-2
USN-8593-1
USN-8595-1
USN-8595-2
USN-8595-3
USN-8596-1
USN-8597-1
USN-8603-1
USN-8606-1
USN-8607-1
USN-8608-1
USN-8609-1
USN-8610-1
USN-8618-1
USN-8619-1
USN-8620-1
USN-8620-2
USN-8620-3
USN-8620-4

Affected Products

Linux Kernel
Opensuse Tumbleweed