From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 608FA451071 for ; Fri, 4 Sep 2026 15:15:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534961; cv=none; b=GtPtAxulPq6Lq6TOMUBpNPjUTXxdX0+7XgaduiNbwZAzk+qNEgi7ATcliO8C1u3LHabbPsH26aAynaXV/GvinFPmxsdormYCvsdejyaCw2N7Zc5b5L+UHSxSwtn7v9CrP+AdLvVTzhS4DtAteqpetzqDWiGZ4uW/qKYATnb4rm4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788534961; c=relaxed/simple; bh=aADzRYtMp1VN7fFbnFThT1hPiSJVwKm7H6+e5UIxAKM=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=IeVWfGtM+r0tmkjjx9MYbPfA43/7glpTyAOjDpN1/6LD0LR66fk2ydQbRVoTvuwLmwoXwvx9+i7BN8phs8iTm4bcVKs/9GzfFCBBVJ1H9toICB3434QM3btemRMLaX4ZTUPGVjGzSQkagr1UAkV6TdgX7gXz0dd+T7CwMU8C6WM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=t1o+9EpV; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="t1o+9EpV" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3D2771F00A3D; Fri, 4 Sep 2026 15:15:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788534956; bh=y4ohnFo/3dtDcpe+6kmo5M4N08wT/jlSbH865OWOtas=; h=From:To:Cc:Subject:Date:Reply-To; b=t1o+9EpVNLwufsBkFn7ih46/9Hnl3nHg8qhfEa1ZRm5r26BAj8n6tc2VWoJLn43pf LM2bKtY7/Y9pEX491GnyOIBXLqCKsYuFuCvAUPN7q/KDod5IPhhzw0ACBktJkUmyPZ 7FkWStgr9UaDypaUU7zUKCQusTbmI7k+34g9EZQA= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80784: mptcp: pm: fix memory leak from alloc-during-teardown race Date: Fri, 4 Sep 2026 17:11:23 +0200 Message-ID: <2026090405-CVE-2026-80784-1faf@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4313; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=31oevwOYSjvqrHGdXytY5ApsmkXdcC/ILMnV6kYyGB4=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmz7neKcf8Pv5/L8uGA/M35x98e/KIW6u6/iX1NQXN0y tqic36HO2JZGASZGGTFFFm+bOM5ur/ikKKXoe1pmDmsTCBDGLg4BWAip20Y5jtwpRqw6lzZPpml TP2R/4tthp++3mOYpyA810JHqmFzpUXezQOXHmrcWBZdDgA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix memory leak from alloc-during-teardown race mptcp_pm_destroy() empties msk->pm.anno_list and msk->pm.userspace_pm_local_addr_list under msk->pm.lock during socket teardown, dropping the lock between the two. A concurrent userspace PM genl ANNOUNCE on the same msk holds a sock reference via mptcp_token_get_sock() and, in mptcp_pm_nl_announce_doit(), calls mptcp_userspace_pm_append_new_local_addr() and mptcp_pm_announced_alloc(). Both take msk->pm.lock briefly to add to their respective lists. Because the genl handler holds a sock reference, mptcp_pm_destroy() may run on the same msk via mptcp_disconnect(), which invokes mptcp_destroy_common() without dropping the sock refcount, before the handler completes. If the lock acquisitions interleave such that mptcp_pm_destroy() empties a list first, the later alloc adds its entry to a list head that nothing else iterates for this msk, and the entry leaks. kmemleak reports both mptcp_pm_add_addr objects (from mptcp_pm_announced_alloc()) and mptcp_pm_addr_entry objects (from mptcp_userspace_pm_append_new_local_addr()) under sustained concurrent ANNOUNCE + close load against the userspace PM. Add an MPTCP_PM_DESTROYING bit in msk->pm.status, set by mptcp_pm_destroy() under pm.lock before the lists are emptied and checked under pm.lock by the alloc paths. Either the alloc takes pm.lock first, in which case its entry is on the list when mptcp_pm_destroy() frees it; or mptcp_pm_destroy() takes pm.lock first, in which case the later alloc observes the bit and refuses. Found by an MPTCP protocol-flow harness extending BRF (arXiv:2305.08782). The Linux kernel CVE team has assigned CVE-2026-80784 to this issue. Affected and fixed versions =========================== Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 6.1.187 with commit f48341830e4202db3fe884b819b2db6740f0537d Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 6.6.154 with commit bb32e9a6a9a9f99eeda16c4efe443400f3e43892 Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 6.12.106 with commit b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804 Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 6.18.47 with commit 9fe5eebb664ecdba88f3fde18062d94b1d1c465f Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 7.1.11 with commit 6c290915a03fc8228b473641025cf762b256dbd2 Issue introduced in 5.19 with commit 9ab4807c84a4aacfc9b4f79cc81254035e0ec361 and fixed in 7.2 with commit efc33b5102ff859bacd390a5f30112d8e0c084c0 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80784 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/mptcp/pm.c net/mptcp/pm_userspace.c net/mptcp/protocol.h Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/f48341830e4202db3fe884b819b2db6740f0537d https://git.kernel.org/stable/c/bb32e9a6a9a9f99eeda16c4efe443400f3e43892 https://git.kernel.org/stable/c/b2a0b55bf613bd3e81ed26a847b0f6b8e6b7f804 https://git.kernel.org/stable/c/9fe5eebb664ecdba88f3fde18062d94b1d1c465f https://git.kernel.org/stable/c/6c290915a03fc8228b473641025cf762b256dbd2 https://git.kernel.org/stable/c/efc33b5102ff859bacd390a5f30112d8e0c084c0