{"id":"DEBIAN-CVE-2024-46858","details":"In the Linux kernel, the following vulnerability has been resolved:  mptcp: pm: Fix uaf in __timer_delete_sync  There are two paths to access mptcp_pm_del_add_timer, result in a race condition:       CPU1\t\t\t\tCPU2      ====                               ====      net_rx_action      napi_poll                          netlink_sendmsg      __napi_poll                        netlink_unicast      process_backlog                    netlink_unicast_kernel      __netif_receive_skb                genl_rcv      __netif_receive_skb_one_core       netlink_rcv_skb      NF_HOOK                            genl_rcv_msg      ip_local_deliver_finish            genl_family_rcv_msg      ip_protocol_deliver_rcu            genl_family_rcv_msg_doit      tcp_v4_rcv                         mptcp_pm_nl_flush_addrs_doit      tcp_v4_do_rcv                      mptcp_nl_remove_addrs_list      tcp_rcv_established                mptcp_pm_remove_addrs_and_subflows      tcp_data_queue                     remove_anno_list_by_saddr      mptcp_incoming_options             mptcp_pm_del_add_timer      mptcp_pm_del_add_timer             kfree(entry)  In remove_anno_list_by_saddr(running on CPU2), after leaving the critical zone protected by \"pm.lock\", the entry will be released, which leads to the occurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).  Keeping a reference to add_timer inside the lock, and calling sk_stop_timer_sync() with this reference, instead of \"entry-\u003eadd_timer\".  Move list_del(&entry-\u003elist) to mptcp_pm_del_add_timer and inside the pm lock, do not directly access any members of the entry outside the pm lock, which can avoid similar \"entry-\u003ex\" uaf.","modified":"2026-09-15T09:02:58.239436837Z","published":"2024-09-27T13:15:17.353Z","upstream":["CVE-2024-46858"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2024-46858"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.112-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46858.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46858.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.10.11-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2024-46858.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}