Affects Linux kernel, widely used; potential kernel instability from data-race.
CVE-2026-46137
Kernel MPTCP ADD_ADDR timer race may cause data races.
Is CVE-2026-46137 being exploited?
Not confirmed. CVE-2026-46137 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.43% probability of exploitation in the next 30 days.
How severe is CVE-2026-46137?
CVE-2026-46137 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-46137?
Yes. A fix has been recorded for CVE-2026-46137. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-46137 affect?
CVE-2026-46137 affects Linux kernel (MPTCP). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-46137?
Upgrade to patched kernel version and reboot.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Data race in mptcp_pm_add_timer() (softirq) may crash kernel or degrade networking.
Patch when possible
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < d9b272a85fe6b8f993e37915311e4038c814a533
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < 23079e0b7742ec114d3507c3e3aad01b7b69e4af
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < b35605e1f1e877038c8c9d499babbc891cdd234f
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < 013dcdc1961543b9a3433466bc8c79a2f4ca75b5
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < 6e4710d7d8782cb61af29a7e7111ddfc38b9e1a3
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < 2ad56e434199ca24a812bb353667aa1c3860f513
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < cc3c0399361efaaf7ae64262eb3f70829b1189c6
- affected>= 00cfd77b9063dcdf3628a7087faba60de85a9cc8 and < 5cd6e0ad79d2615264f63929f8b457ad97ae550d
- affected5.10
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.