CVE-2026-23169: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race in mptcp_pm_nl_flush_addrs_doit() syzbot and Eulgyu Kim reported crashes in mptcp_pm_nl_get_local_id() and/or mptcp_pm_nl_is_backup() Root cause is list_splice_init() in mptcp_pm_nl_flush_addrs_doit() which is not RCU ready. list_splice_init_rcu() can not be called here while holding pernet->lock spinlock. Many thanks to Eulgyu Kim for providing a repro and testing our patches.

Affected products

  • Linux Linux Kernel: from 5.11, before 5.15.201 (fixed in 5.15.201); from 5.16, before 6.1.164 (fixed in 6.1.164); from 6.2, before 6.6.125 (fixed in 6.6.125); from 6.7, before 6.12.72 (fixed in 6.12.72); from 6.13, before 6.18.9 (fixed in 6.18.9); version 6.19 only

Published 2026-02-14. Last modified 2026-06-17.