CVE-2026-31669

Description

A flaw was found in the Linux kernel's Multipath TCP (MPTCP) implementation. Due to incorrect memory allocation for IPv6 subflow child sockets, a use-after-free vulnerability exists. A remote attacker could exploit this by triggering concurrent lookups in the kernel's hash table, potentially leading to a denial of service or arbitrary code execution.

Statement

A slab use after free can occur in the MPTCP IPv6 subflow path because tcpv6_prot_override may end up with a NULL slab cache pointer and child sockets are then allocated from a non RCU safe kmalloc cache. Lockless ehash lookups rely on SLAB_TYPESAFE_BY_RCU for socket memory stability under rcu_read_lock. When the affected sockets are freed without SOCK_RCU_FREE the memory can be reused immediately and a concurrent __inet_lookup_established lookup can access freed memory. This is at least a denial of service via kernel crash and it is a memory corruption class issue that may allow confidentiality or integrity impact in a worst case scenario. The issue can be network reachable via MPTCP over IPv6, but there is no known attack scenario for now. There is no confirmed practical trigger scenario under default configurations. It appears to require specific non-default preconditions (MPTCP/IPv6 runtime conditions and vulnerable child socket creation paths) that are not known to be reachable by default, so this is the reason to keep this one "Moderate" impact level.

Mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.5N/A9.8
Attack VectorAdjacent NetworkN/ANetwork
Attack ComplexityHighN/ALow
Privileges RequiredNoneN/ANone
User InteractionNoneN/ANone
ScopeUnchangedN/AUnchanged
ConfidentialityHighN/AHigh
Integrity ImpactHighN/AHigh
Availability ImpactHighN/AHigh

Vector

Red Hat: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

cve.org: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Understanding the Weakness (CWE)

Integrity,Availability,Confidentiality

Technical Impact: Modify Memory; DoS: Crash, Exit, or Restart; Execute Unauthorized Code or Commands

This weakness may result in the corruption of memory, and perhaps instructions, possibly leading to a crash. If the corrupted memory can be effectively controlled, it may be possible to execute arbitrary code.

Frequently Asked Questions

Want to get errata notifications? Sign up here.