Description
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end. Some (unlikely) checks were returning directly instead of calling sock_put() to decrease the refcount. Jump to a new -exit- label to call __sock_put() (which will become sock_put() in the next commit) to fix this potential leak. While at it, drop the -!msk- check which cannot happen because it is never reset, and explicitly mark the remaining one as -unlikely-.
CVSS 5.5EPSS 0.127%Risk 0.56
View source- Published
- 2026-05-28 10:16:31
- Affected versions
- unknown
- Type
- Core software
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Operating systems
- Linux