CVE-2026-68170
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix stale skb->sk reference on subflow close
The backlog list is updated by mptcpdataready() under
mptcpdatalock(). The cleanup of backlog references to a closing
subflow, however, was performed in mptcpclosessk(), before
_mptcpclose_ssk() acquires the ssk lock, and while holding neither
the ssk lock nor mptcpdatalock().
Because that traversal ran without mptcpdatalock(), concurrent softirq
RX processing on another CPU (subflowdataready() -> mptcpdataready()
-> _mptcpaddbacklog(), under mptcpdata_lock()) could add a backlog
entry referencing the ssk while the cleanup loop was in progress. Such
an entry could be missed by the cleanup, or the concurrent list update
could corrupt the traversal, leaving skb->sk pointing at the ssk after
it is freed.
A later mptcpbacklogpurge() then dereferences the stale pointer,
triggering a warning in inetsockdestruct() (ssk->skrmemalloc != 0)
followed by a use-after-free in mptcpbacklogpurge().
Fix this by moving the backlog cleanup into _mptcpclose_ssk(), after
subflow->closing is set to 1 and while the ssk lock is still held,
serialized under mptcpdatalock(). The cleanup runs only on the push
path (MPTCPCFPUSH), where backlog references accumulate; on other
teardown paths the caller already handles cleanup.
With subflow->closing set and mptcpdatalock() held across the purge,
any concurrent mptcpdataready() either completes its enqueue before
the purge runs and is caught, or observes closing=1 and bails out. Once
mptcpdataunlock() is reached, no new skb referencing the ssk can be
enqueued, so the cleanup is exhaustive.
Remove the unprotected traversal from mptcpclosessk() entirely.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/625fc6060864889fe3d370cdeffbbab762af3cb4, https://git.kernel.org/stable/c/bd7aae448f6ee9d82599a4474664de1e6e91a535, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68170.json, https://nvd.nist.gov/vuln/detail/CVE-2026-68170, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git