CVE-2024-46858: mptcp: pm: Fix uaf in __timer_delete_sync
In the Linux kernel, the following vulnerability has been resolved:
mptcp: pm: Fix uaf in __timer_delete_sync
There are two paths to access mptcp_pm_del_add_timer, result in a race
condition:
CPU1 CPU2
==== ====
net_rx_action
napi_poll netlink_sendmsg
__napi_poll netlink_unicast
process_backlog netlink_unicast_kernel
__netif_receive_skb genl_rcv
__netif_receive_skb_one_core netlink_rcv_skb
NF_HOOK genl_rcv_msg
ip_local_deliver_finish genl_family_rcv_msg
ip_protocol_deliver_rcu genl_family_rcv_msg_doit
tcp_v4_rcv mptcp_pm_nl_flush_addrs_doit
tcp_v4_do_rcv mptcp_nl_remove_addrs_list
tcp_rcv_established mptcp_pm_remove_addrs_and_subflows
tcp_data_queue remove_anno_list_by_saddr
mptcp_incoming_options mptcp_pm_del_add_timer
mptcp_pm_del_add_timer kfree(entry)
In remove_anno_list_by_saddr(running on CPU2), after leaving the critical
zone protected by "pm.lock", the entry will be released, which leads to the
occurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).
Keeping a reference to add_timer inside the lock, and calling
sk_stop_timer_sync() with this reference, instead of "entry->add_timer".
Move list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock,
do not directly access any members of the entry outside the pm lock, which
can avoid similar "entry->x" uaf.
Security readout for executives and security teams
Plain-English summary
CVE-2024-46858 is a Linux kernel memory-safety flaw in Multipath TCP. A timing race can cause use-after-free behavior, which may crash affected systems or create deeper kernel risk. The public bundle does not provide CVSS, CWE, or confirmed exploitation evidence.
Executive priority
Schedule normal-to-expedited kernel patching based on MPTCP usage and system criticality. The absence of CVSS and exploitation evidence limits urgency, but kernel use-after-free issues deserve timely remediation.
Technical view
The flaw is in the MPTCP path manager around mptcp_pm_del_add_timer. Concurrent packet-processing and netlink paths can free an address entry while another CPU still accesses its timer. Stable fixes keep the timer reference under the pm lock and avoid entry member access outside that lock.
Likely exposure
Exposure is most relevant to Linux systems running affected kernel versions with MPTCP support present, especially where MPTCP is enabled or managed through netlink. The bundle lists Linux kernel versions including 5.10 through 6.11 ranges and Debian LTS advisories.
Exploitation context
The source bundle marks KEV as false and provides no public evidence of active exploitation. No exploitability rating is supplied. Treat this as a kernel race condition requiring patch verification, not as confirmed in-the-wild exploitation.
Researcher notes
Focus validation on the race between receive-path MPTCP option handling and netlink address flushing. The fix moves list deletion and timer reference handling inside locking boundaries to prevent post-free entry access.
Mitigation direction
Apply vendor kernel updates containing the referenced stable MPTCP fixes.
Prioritize internet-facing, multi-tenant, or MPTCP-enabled Linux systems.
Track Debian LTS advisories if using affected Debian kernel packages.
Check distribution guidance before relying on configuration workarounds.
Reboot into the fixed kernel after package installation.
Validation and detection
Inventory running kernel versions across Linux hosts.
Compare kernel packages with vendor advisories and fixed stable commits.
Confirm MPTCP usage or enablement on prioritized systems.
Verify the fixed kernel is active after reboot.
Document that KEV is false in the provided bundle.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2024-46858 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.