cbcvebase.
CVE-2026-46137
published 2026-05-28

CVE-2026-46137: In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is…

PriorityP344critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.43%
35.0th percentile
In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: ADD_ADDR rtx: fix potential data-race This mptcp_pm_add_timer() helper is executed as a timer callback in softirq context. To avoid any data races, the socket lock needs to be held with bh_lock_sock(). If the socket is in use, retry again soon after, similar to what is done with the keepalive timer.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
linuxlinux
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < d9b272a85fe6b8f993e37915311e4038c814a533d9b272a85fe6b8f993e37915311e4038c814a533
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 23079e0b7742ec114d3507c3e3aad01b7b69e4af23079e0b7742ec114d3507c3e3aad01b7b69e4af
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < b35605e1f1e877038c8c9d499babbc891cdd234fb35605e1f1e877038c8c9d499babbc891cdd234f
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 013dcdc1961543b9a3433466bc8c79a2f4ca75b5013dcdc1961543b9a3433466bc8c79a2f4ca75b5
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 6e4710d7d8782cb61af29a7e7111ddfc38b9e1a36e4710d7d8782cb61af29a7e7111ddfc38b9e1a3
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 2ad56e434199ca24a812bb353667aa1c3860f5132ad56e434199ca24a812bb353667aa1c3860f513
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < cc3c0399361efaaf7ae64262eb3f70829b1189c6cc3c0399361efaaf7ae64262eb3f70829b1189c6
linuxlinux>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 < 5cd6e0ad79d2615264f63929f8b457ad97ae550d5cd6e0ad79d2615264f63929f8b457ad97ae550d
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 5.10 < 5.10.2595.10.259
linuxlinux_kernel>= 5.11 < 5.15.2105.15.210
linuxlinux_kernel>= 5.16 < 6.1.1766.1.176
linuxlinux_kernel>= 6.13 < 6.18.306.18.30
linuxlinux_kernel>= 6.19 < 7.0.77.0.7
linuxlinux_kernel>= 6.2 < 6.6.1416.6.141
linuxlinux_kernel>= 6.7 < 6.12.916.12.91
ubuntulinux
ubuntulinux-aws
ubuntulinux-aws-5.15
ubuntulinux-aws-fips
ubuntulinux-azure
ubuntulinux-azure-5.15

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_ubuntu8.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.