Junglewise Threat Intelligence

CVE-2026-46170: Linux Kernel deadlock and resource leak in MPTCP ADD_ADDR retransmission

CVE-2026-46170 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could cause a system to hang or fail to properly clean up network resources. This occurs specifically when using MultiPath TCP (MPTCP), a feature that allows devices to use multiple network paths simultaneously. If exploited, this could lead to a denial-of-service condition where the system becomes unresponsive or experiences memory leaks.

Technical details

A vulnerability exists in the MPTCP Path Manager (PM) within the Linux kernel due to improper socket reference counting and timer synchronization during ADD_ADDR retransmissions. When a retransmission timer expires, the code incorrectly used __sock_put() instead of sock_put(), potentially failing to free the socket if it was the last reference. Furthermore, a race condition existed where calling sock_put() could trigger sk_free(), which in turn calls sk_stop_timer_sync() on the currently running timer, leading to an indefinite hang (deadlock). The fix introduces a 'timer_done' flag to prevent the timer from attempting to synchronize with itself and ensures proper socket cleanup. This is reachable via network traffic that triggers MPTCP address advertisements and subsequent retransmission timeouts.

Affected products

  • Linux Linux Kernel All versions prior to the fix in May 2026

Timeline

  • 2026-05-05: patched: Initial patch authored by Matthieu Baerts
  • 2026-05-28: advisory: CVE-2026-46170 published to NVD

References