CVE-2026-46137
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: ADD_ADDR rtx: fix potential data-race
This mptcppmadd_timer() helper is executed as a timer callback in
softirq context. To avoid any data races, the socket lock needs to be
held with bhlocksock().
If the socket is in use, retry again soon after, similar to what is done
with the keepalive timer.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/013dcdc1961543b9a3433466bc8c79a2f4ca75b5, https://git.kernel.org/stable/c/23079e0b7742ec114d3507c3e3aad01b7b69e4af, https://git.kernel.org/stable/c/2ad56e434199ca24a812bb353667aa1c3860f513, https://git.kernel.org/stable/c/5cd6e0ad79d2615264f63929f8b457ad97ae550d, https://git.kernel.org/stable/c/6e4710d7d8782cb61af29a7e7111ddfc38b9e1a3, https://git.kernel.org/stable/c/b35605e1f1e877038c8c9d499babbc891cdd234f, https://git.kernel.org/stable/c/cc3c0399361efaaf7ae64262eb3f70829b1189c6, https://git.kernel.org/stable/c/d9b272a85fe6b8f993e37915311e4038c814a533, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46137.json, https://nvd.nist.gov/vuln/detail/CVE-2026-46137, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git