CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-31669

Critical · CVSS 9.8

Linux Kernel MPTCP — Use-After-Free (CWE-416) - slab-use-after-free via missing SLAB_TYPESAFE_BY_RCU on MPTCP v6 subflow slab cache

CVSS
9.8
nvd
EPSS
0.40%
32th pct
KEV
No
Class
oss containerizable
CWE-416

Description

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU to guarantee socket memory stability during RCU read-side critical sections. Both tcp_prot and tcpv6_prot have their slab caches created with this flag via proto_register(). However, MPTCP's mptcp_subflow_init() copies tcpv6_prot into tcpv6_prot_override during inet_init() (fs_initcall, level 5), before inet6_init() (module_init/device_initcall, level 6) has called proto_register(&tcpv6_prot). At that point, tcpv6_prot.slab is still NULL, so tcpv6_prot_override.slab remains NULL permanently. This causes MPTCP v6 subflow child sockets to be allocated via kmalloc (falling into kmalloc-4k) instead of the TCPv6 slab cache. The kmalloc-4k cache lacks SLAB_TYPESAFE_BY_RCU, so when these sockets are freed without SOCK_RCU_FREE (which is cleared for child sockets by design), the memory can be immediately reused. Concurrent ehash lookups under rcu_read_lock can then access freed memory, triggering a slab-use-after-free in __inet_lookup_established. Fix this by splitting the IPv6-specific initialization out of mptcp_subflow_init() into a new mptcp_subflow_v6_init(), called from mptcp_proto_v6_init() before protocol registration. This ensures tcpv6_prot_override.slab correctly inherits the SLAB_TYPESAFE_BY_RCU slab cache.

Search profile — drives PoC discovery

Symbols mptcp_subflow_initmptcp_subflow_v6_initmptcp_proto_v6_inittcpv6_prot_override__inet_lookup_establishedSLAB_TYPESAFE_BY_RCUSOCK_RCU_FREEmptcp_subflow_initproto_registertcpv6_protkmalloc-4kinet_initinet6_initfs_initcallmodule_init
Keywords CVE-2026-31669Linux kernel MPTCP slab-use-after-freemptcp_subflow_v6_inittcpv6_prot_override SLAB_TYPESAFE_BY_RCU__inet_lookup_established use-after-freeMPTCP v6 subflow slab cache NULLmptcp_subflow_init tcpv6_prot_overrideMPTCP ehash lockless use-after-freemptcp proto_register slab NULL fix
Versions: Linux kernel versions prior to stable fixes: 15fa9ead4d5e, 3fd6547f5b8a, 9b55b253907e, b313e9037d98, eb9c6aeb512f

Affected packages

Linux Kernel 5.12.0 → 5.15.203
Linux Kernel 5.16.0 → 6.1.169
Linux Kernel 6.13.0 → 6.18.23
Linux Kernel 6.19.0 → 6.19.13
Linux Kernel 6.2.0 → 6.6.135
Linux Kernel 6.7.0 → 6.12.82

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z