Junglewise Threat Intelligence

CVE-2026-31669: Linux Kernel slab-use-after-free in MPTCP IPv6 subflow

CVE-2026-31669 · Severity: critical · CVSS 9.8 · Published 2026-04-24

Technologies: Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability exists in the Linux kernel's MultiPath TCP (MPTCP) implementation that could lead to system instability or unauthorized access. The issue occurs because certain network connection data is handled incorrectly in memory, allowing the system to potentially reuse memory that is still being accessed by other processes. This could result in a system crash or allow an attacker to interfere with network traffic on affected devices, including certain industrial controllers.

Technical details

A slab-use-after-free vulnerability exists in the Linux kernel's MPTCP implementation within the __inet_lookup_established function. The root cause is a race condition during initialization where mptcp_subflow_init() copies tcpv6_prot into tcpv6_prot_override before proto_register() is called for IPv6. This results in the MPTCP v6 subflow child sockets being allocated via kmalloc instead of the dedicated TCPv6 slab cache, missing the SLAB_TYPESAFE_BY_RCU protection. Consequently, when these sockets are freed, their memory can be immediately reused while concurrent lockless ehash table lookups are still occurring. An attacker can exploit this via network-based MPTCP traffic to trigger a use-after-free condition. Patches have been released for multiple stable kernel branches.

Affected products

  • Linux Linux Kernel Fixed in 6.14+ and various stable backports
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5, V3.1.6

Timeline

  • 2026-04-06: other: Patch submitted by developer
  • 2026-04-24: disclosed: CVE published
  • 2026-07-14: advisory: Siemens industrial product advisory updated

References

Related threats