{"id":"CVE-2026-46158","title":"mptcp: pm: ADD_ADDR rtx: always decrease sk refcount","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at …","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < f5555a6d7c472849fdf2b426e3d0a85103118793","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < e9ba34301d2e90f63f97c76ad9eb98e5250fe961","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 81d8142148164176385c279c7c1e1d581867423d","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 9426265e157dd77ec237c795901ed4dea6d69b5c","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < b41dd76f3b9735096c21d3e799a2b9fe36498d57","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < acd3d3562315c99f3c0db16f0fcc5f0306638982","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 25e37407442b8766ec2cf52fb4e31b5c3d3aeeae","Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 9634cb35af17019baec21ca648516ce376fa10e6","Linux 5.10"],"published":"2026-05-28","updated":"2026-09-14","sourceUpdated":"2026-09-14T11:58:23.714Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-46158","references":[{"url":"https://git.kernel.org/stable/c/f5555a6d7c472849fdf2b426e3d0a85103118793"},{"url":"https://git.kernel.org/stable/c/e9ba34301d2e90f63f97c76ad9eb98e5250fe961"},{"url":"https://git.kernel.org/stable/c/81d8142148164176385c279c7c1e1d581867423d"},{"url":"https://git.kernel.org/stable/c/9426265e157dd77ec237c795901ed4dea6d69b5c"},{"url":"https://git.kernel.org/stable/c/b41dd76f3b9735096c21d3e799a2b9fe36498d57"},{"url":"https://git.kernel.org/stable/c/acd3d3562315c99f3c0db16f0fcc5f0306638982"},{"url":"https://git.kernel.org/stable/c/25e37407442b8766ec2cf52fb4e31b5c3d3aeeae"},{"url":"https://git.kernel.org/stable/c/9634cb35af17019baec21ca648516ce376fa10e6"}],"tags":["cve.org"],"epss":0.00128,"epssPercentile":0.02808,"ingestedAt":"2026-09-14T15:23:07.458Z","slug":"CVE-2026-46158","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: ADD_ADDR rtx: always decrease sk refcount\n\nWhen an ADD_ADDR is retransmitted, the sk is held in sk_reset_timer().\nIt should then be released in all cases at the end.\n\nSome (unlikely) checks were returning directly instead of calling\nsock_put() to decrease the refcount. Jump to a new 'exit' label to call\n__sock_put() (which will become sock_put() in the next commit) to fix\nthis potential leak.\n\nWhile at it, drop the '!msk' check which cannot happen because it is\nnever reset, and explicitly mark the remaining one as \"unlikely\".\n\n## Affected\n\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < f5555a6d7c472849fdf2b426e3d0a85103118793`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < e9ba34301d2e90f63f97c76ad9eb98e5250fe961`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 81d8142148164176385c279c7c1e1d581867423d`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 9426265e157dd77ec237c795901ed4dea6d69b5c`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < b41dd76f3b9735096c21d3e799a2b9fe36498d57`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < acd3d3562315c99f3c0db16f0fcc5f0306638982`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 25e37407442b8766ec2cf52fb4e31b5c3d3aeeae`\n- `Linux >= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 9634cb35af17019baec21ca648516ce376fa10e6`\n- `Linux 5.10`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}