{"id":"CVE-2026-31669","title":"mptcp: fix slab-use-after-free in __inet_lookup_established","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix slab-use-after-free in __inet_lookup_established\n\nThe ehash table lookups are lockless and rely on\nSLAB_TYPESAFE_BY_RCU to guarantee socket memory stability\n…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","vendor":"Linux","product":"Linux","affected":["Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < f6e1f25fa5e733570f6d6fe37a4dfed2a0deba47","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < fb1f54b7d16f393b8b65d328410f78b4beea8fcc","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 3fd6547f5b8ac99687be6d937a0321efda760597","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < eb9c6aeb512f877cf397deb1e4526f646c70e4a7","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 15fa9ead4d5e6b6b9c794e84144146c917f2cb62","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < b313e9037d98c13938740e5ebda7852929366dff","Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 9b55b253907e7431210483519c5ad711a37dafa1","Linux 5.12"],"published":"2026-04-24","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:47:59.039Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-31669","references":[{"url":"https://git.kernel.org/stable/c/f6e1f25fa5e733570f6d6fe37a4dfed2a0deba47"},{"url":"https://git.kernel.org/stable/c/fb1f54b7d16f393b8b65d328410f78b4beea8fcc"},{"url":"https://git.kernel.org/stable/c/3fd6547f5b8ac99687be6d937a0321efda760597"},{"url":"https://git.kernel.org/stable/c/eb9c6aeb512f877cf397deb1e4526f646c70e4a7"},{"url":"https://git.kernel.org/stable/c/15fa9ead4d5e6b6b9c794e84144146c917f2cb62"},{"url":"https://git.kernel.org/stable/c/b313e9037d98c13938740e5ebda7852929366dff"},{"url":"https://git.kernel.org/stable/c/9b55b253907e7431210483519c5ad711a37dafa1"}],"tags":["cve.org"],"epss":0.00459,"epssPercentile":0.39097,"ingestedAt":"2026-09-08T15:33:26.989Z","slug":"CVE-2026-31669","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix slab-use-after-free in __inet_lookup_established\n\nThe ehash table lookups are lockless and rely on\nSLAB_TYPESAFE_BY_RCU to guarantee socket memory stability\nduring RCU read-side critical sections. Both tcp_prot and\ntcpv6_prot have their slab caches created with this flag\nvia proto_register().\n\nHowever, MPTCP's mptcp_subflow_init() copies tcpv6_prot into\ntcpv6_prot_override during inet_init() (fs_initcall, level 5),\nbefore inet6_init() (module_init/device_initcall, level 6) has\ncalled proto_register(&tcpv6_prot). At that point,\ntcpv6_prot.slab is still NULL, so tcpv6_prot_override.slab\nremains NULL permanently.\n\nThis causes MPTCP v6 subflow child sockets to be allocated via\nkmalloc (falling into kmalloc-4k) instead of the TCPv6 slab\ncache. The kmalloc-4k cache lacks SLAB_TYPESAFE_BY_RCU, so\nwhen these sockets are freed without SOCK_RCU_FREE (which is\ncleared for child sockets by design), the memory can be\nimmediately reused. Concurrent ehash lookups under\nrcu_read_lock can then access freed memory, triggering a\nslab-use-after-free in __inet_lookup_established.\n\nFix this by splitting the IPv6-specific initialization out of\nmptcp_subflow_init() into a new mptcp_subflow_v6_init(), called\nfrom mptcp_proto_v6_init() before protocol registration. This\nensures tcpv6_prot_override.slab correctly inherits the\nSLAB_TYPESAFE_BY_RCU slab cache.\n\n## Affected\n\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < f6e1f25fa5e733570f6d6fe37a4dfed2a0deba47`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < fb1f54b7d16f393b8b65d328410f78b4beea8fcc`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 3fd6547f5b8ac99687be6d937a0321efda760597`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < eb9c6aeb512f877cf397deb1e4526f646c70e4a7`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 15fa9ead4d5e6b6b9c794e84144146c917f2cb62`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < b313e9037d98c13938740e5ebda7852929366dff`\n- `Linux >= b19bc2945b40b9fd38e835700907ffe8534ef0de < 9b55b253907e7431210483519c5ad711a37dafa1`\n- `Linux 5.12`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}