← Volver al buscador de CVEs

CVE-2026-46158

Linux Kernel

Descripción

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: always decrease sk refcount When an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer(). It should then be released in all cases at the end. Some (unlikely) checks were returning directly instead of calling sock_put() to decrease the refcount. Jump to a new -exit- label to call __sock_put() (which will become sock_put() in the next commit) to fix this potential leak. While at it, drop the -!msk- check which cannot happen because it is never reset, and explicitly mark the remaining one as -unlikely-.

CVSS 5.5EPSS 0.127%Riesgo 0.56
Ver fuente
Publicación
2026-05-28 10:16:31
Versiones afectadas
unknown
Tipo
Core software
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Sistemas operativos
Linux