Vulnerability Bulletins

CVE-2026-46168

   
Affected software LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

mptcp: fix scheduling with atomic in timestamp sockopt

Using lock_sock_fast() (atomic context) around sock_set_timestamp()
and sock_set_timestamping() is unsafe, as both helpers can sleep.

Replace lock_sock_fast() with sleepable lock_sock()/release_sock()
to avoid scheduling while atomic panic.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-46168