{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80784","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.792Z","datePublished":"2026-09-04T15:12:56.125Z","dateUpdated":"2026-09-04T15:12:56.125Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-04T15:12:56.125Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: fix memory leak from alloc-during-teardown race\n\nmptcp_pm_destroy() empties msk->pm.anno_list and\nmsk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket\nteardown, dropping the lock between the two.\n\nA concurrent userspace PM genl ANNOUNCE on the same msk holds a sock\nreference via mptcp_token_get_sock() and, in\nmptcp_pm_nl_announce_doit(), calls\nmptcp_userspace_pm_append_new_local_addr() and\nmptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to\ntheir respective lists. Because the genl handler holds a sock reference,\nmptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which\ninvokes mptcp_destroy_common() without dropping the sock refcount,\nbefore the handler completes.\n\nIf the lock acquisitions interleave such that mptcp_pm_destroy() empties\na list first, the later alloc adds its entry to a list head that nothing\nelse iterates for this msk, and the entry leaks. kmemleak reports both\nmptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and\nmptcp_pm_addr_entry objects (from\nmptcp_userspace_pm_append_new_local_addr()) under sustained concurrent\nANNOUNCE + close load against the userspace PM.\n\nAdd an MPTCP_PM_DESTROYING bit in msk->pm.status, set by\nmptcp_pm_destroy() under pm.lock before the lists are emptied and\nchecked under pm.lock by the alloc paths. Either the alloc takes pm.lock\nfirst, in which case its entry is on the list when mptcp_pm_destroy()\nfrees it; or mptcp_pm_destroy() takes pm.lock first, in which case the\nlater alloc observes the bit and refuses.\n\nFound by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782)."}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mptcp/pm.c","net/mptcp/pm_userspace.c","net/mptcp/protocol.h"],"versions":[{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"f48341830e4202db3fe884b819b2db6740f0537d","status":"affected","versionType":"git"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"bb32e9a6a9a9f99eeda16c4efe443400f3e43892","status":"affected","versionType":"git"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804","status":"affected","versionType":"git"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"9fe5eebb664ecdba88f3fde18062d94b1d1c465f","status":"affected","versionType":"git"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"6c290915a03fc8228b473641025cf762b256dbd2","status":"affected","versionType":"git"},{"version":"9ab4807c84a4aacfc9b4f79cc81254035e0ec361","lessThan":"efc33b5102ff859bacd390a5f30112d8e0c084c0","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/mptcp/pm.c","net/mptcp/pm_userspace.c","net/mptcp/protocol.h"],"versions":[{"version":"5.19","status":"affected"},{"version":"0","lessThan":"5.19","status":"unaffected","versionType":"semver"},{"version":"6.1.187","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.154","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.106","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.47","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.11","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.1.187"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.6.154"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.12.106"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"6.18.47"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.1.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.19","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/f48341830e4202db3fe884b819b2db6740f0537d"},{"url":"https://git.kernel.org/stable/c/bb32e9a6a9a9f99eeda16c4efe443400f3e43892"},{"url":"https://git.kernel.org/stable/c/b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804"},{"url":"https://git.kernel.org/stable/c/9fe5eebb664ecdba88f3fde18062d94b1d1c465f"},{"url":"https://git.kernel.org/stable/c/6c290915a03fc8228b473641025cf762b256dbd2"},{"url":"https://git.kernel.org/stable/c/efc33b5102ff859bacd390a5f30112d8e0c084c0"}],"title":"mptcp: pm: fix memory leak from alloc-during-teardown race","x_generator":{"engine":"bippy-1.2.0"}}}}