Use-after-free in Linux kernel - CVE-2026-68169
Published: August 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use-after-free in mptcp_userspace_pm_get_local_id() in the MPTCP userspace path manager when processing overlapping MP_JOIN SYN and MPTCP_PM_CMD_SUBFLOW_DESTROY operations. A local user can trigger a race condition to cause a denial of service.
The race window is narrow and was reproduced with a locally constructed stress test.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68169
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/31ce5af66891f79998fb2e8b8df08e3c98fd72e3
- https://git.kernel.org/stable/c/40dde4b5d98279471a70e5c8bb713182738c00d9
- https://git.kernel.org/stable/c/9bc6d5e4ca9f3cbb41d43400b3a31cb0403796c9
- https://git.kernel.org/stable/c/d2c3760b45f2f481a4dd4c5adef4a29dfabd948f
- https://git.kernel.org/stable/c/d64f6c02495f3fad674038cfa7ec049671b59e7b