← Zurück zur CVE-Suche

CVE-2026-46158

Linux Kernel

Beschreibung

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end. Some (unlikely) checks were returning directly instead of calling sock_put() to decrease the refcount. Jump to a new -exit- label to call __sock_put() (which will become sock_put() in the next commit) to fix this potential leak. While at it, drop the -!msk- check which cannot happen because it is never reset, and explicitly mark the remaining one as -unlikely-.

CVSS 5.5EPSS 0.127%Risiko 0.56
Quelle öffnen
Veröffentlicht
2026-05-28 10:16:31
Betroffene Versionen
unknown
Typ
Core software
Vektor
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Betriebssysteme
Linux