LiveActive security incident?Get immediate response
CVE Record

CVE-2024-46858: mptcp: pm: Fix uaf in __timer_delete_sync

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== net_rx_action napi_poll netlink_sendmsg __napi_poll netlink_unicast process_backlog netlink_unicast_kernel __netif_receive_skb genl_rcv __netif_receive_skb_one_core netlink_rcv_skb NF_HOOK genl_rcv_msg ip_local_deliver_finish genl_family_rcv_msg ip_protocol_deliver_rcu genl_family_rcv_msg_doit tcp_v4_rcv mptcp_pm_nl_flush_addrs_doit tcp_v4_do_rcv mptcp_nl_remove_addrs_list tcp_rcv_established mptcp_pm_remove_addrs_and_subflows tcp_data_queue remove_anno_list_by_saddr mptcp_incoming_options mptcp_pm_del_add_timer mptcp_pm_del_add_timer kfree(entry) In remove_anno_list_by_saddr(running on CPU2), after leaving the critical zone protected by "pm.lock", the entry will be released, which leads to the occurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1). Keeping a reference to add_timer inside the lock, and calling sk_stop_timer_sync() with this reference, instead of "entry->add_timer". Move list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock, do not directly access any members of the entry outside the pm lock, which can avoid similar "entry->x" uaf.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

CVE-2024-46858 is a Linux kernel memory-safety flaw in Multipath TCP. A timing race can cause use-after-free behavior, which may crash affected systems or create deeper kernel risk. The public bundle does not provide CVSS, CWE, or confirmed exploitation evidence.

Executive priority

Schedule normal-to-expedited kernel patching based on MPTCP usage and system criticality. The absence of CVSS and exploitation evidence limits urgency, but kernel use-after-free issues deserve timely remediation.

Technical view

The flaw is in the MPTCP path manager around mptcp_pm_del_add_timer. Concurrent packet-processing and netlink paths can free an address entry while another CPU still accesses its timer. Stable fixes keep the timer reference under the pm lock and avoid entry member access outside that lock.

Likely exposure

Exposure is most relevant to Linux systems running affected kernel versions with MPTCP support present, especially where MPTCP is enabled or managed through netlink. The bundle lists Linux kernel versions including 5.10 through 6.11 ranges and Debian LTS advisories.

Exploitation context

The source bundle marks KEV as false and provides no public evidence of active exploitation. No exploitability rating is supplied. Treat this as a kernel race condition requiring patch verification, not as confirmed in-the-wild exploitation.

Researcher notes

Focus validation on the race between receive-path MPTCP option handling and netlink address flushing. The fix moves list deletion and timer reference handling inside locking boundaries to prevent post-free entry access.

Mitigation direction

  • Apply vendor kernel updates containing the referenced stable MPTCP fixes.
  • Prioritize internet-facing, multi-tenant, or MPTCP-enabled Linux systems.
  • Track Debian LTS advisories if using affected Debian kernel packages.
  • Check distribution guidance before relying on configuration workarounds.
  • Reboot into the fixed kernel after package installation.

Validation and detection

  • Inventory running kernel versions across Linux hosts.
  • Compare kernel packages with vendor advisories and fixed stable commits.
  • Confirm MPTCP usage or enablement on prioritized systems.
  • Verify the fixed kernel is active after reboot.
  • Document that KEV is false in the provided bundle.
Prepared
Confidence
medium
Sources
10

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2024-46858 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
3Timeline events
2ADP providers
9Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: partial

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
CVECVE Program Container
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
LinuxLinux00cfd77b9063dcdf3628a7087faba60de85a9cc8, 00cfd77b9063dcdf3628a7087faba60de85a9cc8, 00cfd77b9063dcdf3628a7087faba60de85a9cc8, 00cfd77b9063dcdf3628a7087faba60de85a9cc8, 00cfd77b9063dcdf3628a7087faba60de85a9cc8, 00cfd77b9063dcdf3628a7087faba60de85a9cc8unaffected
LinuxLinux5.10, 0, 5.10.227, 5.15.168, 6.1.111, 6.6.52, 6.10.11, 6.11affected
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.