SB20260812371 - Use-after-free in Linux kernel mptcp
Published: August 12, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Use-after-free (CVE-ID: CVE-2026-68169)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in mptcp_userspace_pm_get_local_id() in the MPTCP userspace path manager when processing overlapping MP_JOIN SYN and MPTCP_PM_CMD_SUBFLOW_DESTROY operations. A local user can trigger a race condition to cause a denial of service.
The race window is narrow and was reproduced with a locally constructed stress test.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/31ce5af66891f79998fb2e8b8df08e3c98fd72e3
- https://git.kernel.org/stable/c/40dde4b5d98279471a70e5c8bb713182738c00d9
- https://git.kernel.org/stable/c/9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9
- https://git.kernel.org/stable/c/d2c3760b45f2f481a4dd4c5adef4a29dfabd948f
- https://git.kernel.org/stable/c/d64f6c02495f3fad674038cfa7ec049671b59e7b