[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2024-46858":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":21,"duplicate_of":9,"upstream":22,"downstream":23,"duplicates":100,"related":101,"reserved_at":9,"published_at":113,"modified_at":114,"state":115,"summary":116,"references_raw":124,"kevs":159,"epss":160,"epss_history":163,"metrics":430,"affected":436},"CVE-2024-46858","In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: pm: Fix uaf in __timer_delete_sync\n\nThere are two paths to access mptcp_pm_del_add_timer, result in a race\ncondition:\n\n     CPU1\t\t\t\tCPU2\n     ====                               ====\n     net_rx_action\n     napi_poll                          netlink_sendmsg\n     __napi_poll                        netlink_unicast\n     process_backlog                    netlink_unicast_kernel\n     __netif_receive_skb                genl_rcv\n     __netif_receive_skb_one_core       netlink_rcv_skb\n     NF_HOOK                            genl_rcv_msg\n     ip_local_deliver_finish            genl_family_rcv_msg\n     ip_protocol_deliver_rcu            genl_family_rcv_msg_doit\n     tcp_v4_rcv                         mptcp_pm_nl_flush_addrs_doit\n     tcp_v4_do_rcv                      mptcp_nl_remove_addrs_list\n     tcp_rcv_established                mptcp_pm_remove_addrs_and_subflows\n     tcp_data_queue                     remove_anno_list_by_saddr\n     mptcp_incoming_options             mptcp_pm_del_add_timer\n     mptcp_pm_del_add_timer             kfree(entry)\n\nIn remove_anno_list_by_saddr(running on CPU2), after leaving the critical\nzone protected by \"pm.lock\", the entry will be released, which leads to the\noccurrence of uaf in the mptcp_pm_del_add_timer(running on CPU1).\n\nKeeping a reference to add_timer inside the lock, and calling\nsk_stop_timer_sync() with this reference, instead of \"entry->add_timer\".\n\nMove list_del(&entry->list) to mptcp_pm_del_add_timer and inside the pm lock,\ndo not directly access any members of the entry outside the pm lock, which\ncan avoid similar \"entry->x\" uaf.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-416","Use After Free","The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory \"belongs\" to the code that operates on the new pointer.","weakness","Stable","Variant","High",[],[],[],[],[24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88,90,92,94,96,98],{"_key":25},"SUSE-SU-2025:0556-1",{"_key":27},"SUSE-SU-2025:0564-1",{"_key":29},"SUSE-SU-2025:0577-1",{"_key":31},"SUSE-SU-2025:0577-2",{"_key":33},"SUSE-SU-2025:0499-1",{"_key":35},"SUSE-SU-2025:0557-1",{"_key":37},"SUSE-SU-2025:0847-1",{"_key":39},"DLA-4008-1",{"_key":41},"DLA-4075-1",{"_key":43},"DSA-5782-1",{"_key":45},"RHSA-2024:10265",{"_key":47},"RHSA-2024:9605",{"_key":49},"SUSE-SU-2025:20190-1",{"_key":51},"SUSE-SU-2025:20192-1",{"_key":53},"SUSE-SU-2025:20260-1",{"_key":55},"SUSE-SU-2025:20270-1",{"_key":57},"DEBIAN-CVE-2024-46858",{"_key":59},"RHSA-2024:10262",{"_key":61},"RHSA-2024:10281",{"_key":63},"RHSA-2024:9497",{"_key":65},"RHSA-2024:9498",{"_key":67},"RHSA-2024:9500",{"_key":69},"RHSA-2024:9546",{"_key":71},"RHSA-2024:9942",{"_key":73},"RHSA-2024:9943",{"_key":75},"UBUNTU-CVE-2024-46858",{"_key":77},"USN-7154-1",{"_key":79},"USN-7154-2",{"_key":81},"USN-7155-1",{"_key":83},"USN-7156-1",{"_key":85},"USN-7166-1",{"_key":87},"USN-7166-2",{"_key":89},"USN-7166-3",{"_key":91},"USN-7166-4",{"_key":93},"USN-7186-1",{"_key":95},"USN-7186-2",{"_key":97},"USN-7194-1",{"_key":99},"USN-7196-1",[],[102,103,104,105,106,107,108,109,110,111,112],{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":49},{"_key":51},{"_key":53},{"_key":55},"2024-09-27T12:42:49.167Z","2026-05-11T20:37:54.749Z","Modified",{"cisa_kev":117,"cisa_ransomware":117,"cisa_vendor":9,"epss_severity":118,"epss_score":119,"severity":120,"severity_score":4,"severity_version":121,"severity_source":122,"severity_vector":123,"severity_status":115},false,"low",0.00017,"high","v3.1","nvd","CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",[125,130,134,139,143,147,151,155],{"url":126,"sources":127,"tags":129},"https://git.kernel.org/stable/c/0e7814b028cd50b3ff79659d23dfa9da6a1e75e1",[128,122],"cve.org",[],{"url":131,"sources":132,"tags":133},"https://git.kernel.org/stable/c/3554482f4691571fc4b5490c17ae26896e62171c",[128,122],[],{"url":135,"sources":136,"tags":137},"https://git.kernel.org/stable/c/67409b358500c71632116356a0b065f112d7b707",[128,122],[138],"Patch",{"url":140,"sources":141,"tags":142},"https://git.kernel.org/stable/c/6452b162549c7f9ef54655d3fb9977b9192e6e5b",[128,122],[138],{"url":144,"sources":145,"tags":146},"https://git.kernel.org/stable/c/12134a652b0a10064844ea235173e70246eba6dc",[128,122],[138],{"url":148,"sources":149,"tags":150},"https://git.kernel.org/stable/c/b4cd80b0338945a94972ac3ed54f8338d2da2076",[128,122],[138],{"url":152,"sources":153,"tags":154},"https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html",[128,122],[],{"url":156,"sources":157,"tags":158},"https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html",[128,122],[],[],{"date":161,"score":119,"percentile":162},"2026-06-03",0.04336,[164,168,172,175,178,180,183,186,189,192,195,198,201,204,207,211,214,217,220,223,226,229,232,235,237,240,242,245,248,251,254,257,260,263,266,269,272,275,278,281,284,286,289,292,295,298,301,304,307,310,313,316,320,323,326,329,333,336,339,342,345,348,351,354,357,360,363,366,369,372,375,378,380,383,386,388,390,393,396,398,401,403,406,409,412,415,418,421,424,427],{"date":165,"score":166,"percentile":167},"2025-11-04",0.00066,0.2059,{"date":169,"score":170,"percentile":171},"2025-11-05",0.00027,0.0617,{"date":173,"score":170,"percentile":174},"2025-11-06",0.06286,{"date":176,"score":170,"percentile":177},"2025-11-07",0.06301,{"date":179,"score":170,"percentile":177},"2025-11-08",{"date":181,"score":170,"percentile":182},"2025-11-09",0.06288,{"date":184,"score":170,"percentile":185},"2025-11-10",0.06265,{"date":187,"score":170,"percentile":188},"2025-11-11",0.06292,{"date":190,"score":170,"percentile":191},"2025-11-12",0.06335,{"date":193,"score":170,"percentile":194},"2025-11-13",0.06366,{"date":196,"score":170,"percentile":197},"2025-11-14",0.0639,{"date":199,"score":170,"percentile":200},"2025-11-15",0.06419,{"date":202,"score":170,"percentile":203},"2025-11-16",0.06435,{"date":205,"score":170,"percentile":206},"2025-11-17",0.0643,{"date":208,"score":209,"percentile":210},"2025-11-18",0.0009,0.21708,{"date":212,"score":209,"percentile":213},"2025-11-19",0.21719,{"date":215,"score":209,"percentile":216},"2025-11-20",0.21729,{"date":218,"score":170,"percentile":219},"2025-11-21",0.06551,{"date":221,"score":170,"percentile":222},"2025-11-22",0.06533,{"date":224,"score":170,"percentile":225},"2025-11-23",0.06517,{"date":227,"score":170,"percentile":228},"2025-11-24",0.06497,{"date":230,"score":170,"percentile":231},"2025-11-25",0.06496,{"date":233,"score":170,"percentile":234},"2025-11-26",0.06508,{"date":236,"score":170,"percentile":234},"2025-11-27",{"date":238,"score":170,"percentile":239},"2025-11-28",0.0649,{"date":241,"score":170,"percentile":222},"2025-11-29",{"date":243,"score":170,"percentile":244},"2025-11-30",0.06531,{"date":246,"score":170,"percentile":247},"2025-12-01",0.06577,{"date":249,"score":170,"percentile":250},"2025-12-02",0.06587,{"date":252,"score":170,"percentile":253},"2025-12-03",0.06599,{"date":255,"score":170,"percentile":256},"2025-12-04",0.06575,{"date":258,"score":170,"percentile":259},"2025-12-05",0.06625,{"date":261,"score":170,"percentile":262},"2025-12-06",0.06635,{"date":264,"score":170,"percentile":265},"2025-12-07",0.06638,{"date":267,"score":170,"percentile":268},"2025-12-08",0.06642,{"date":270,"score":170,"percentile":271},"2025-12-09",0.06699,{"date":273,"score":170,"percentile":274},"2025-12-10",0.06768,{"date":276,"score":170,"percentile":277},"2025-12-11",0.06774,{"date":279,"score":170,"percentile":280},"2025-12-12",0.06779,{"date":282,"score":170,"percentile":283},"2025-12-13",0.06793,{"date":285,"score":170,"percentile":277},"2025-12-14",{"date":287,"score":170,"percentile":288},"2025-12-15",0.06741,{"date":290,"score":170,"percentile":291},"2025-12-16",0.06764,{"date":293,"score":170,"percentile":294},"2025-12-17",0.06854,{"date":296,"score":170,"percentile":297},"2025-12-18",0.06916,{"date":299,"score":170,"percentile":300},"2025-12-19",0.06913,{"date":302,"score":170,"percentile":303},"2025-12-20",0.06909,{"date":305,"score":170,"percentile":306},"2025-12-21",0.06901,{"date":308,"score":170,"percentile":309},"2025-12-22",0.06853,{"date":311,"score":170,"percentile":312},"2025-12-23",0.06846,{"date":314,"score":170,"percentile":315},"2025-12-24",0.0687,{"date":317,"score":318,"percentile":319},"2025-12-25",0.00026,0.06521,{"date":321,"score":318,"percentile":322},"2025-12-26",0.06512,{"date":324,"score":318,"percentile":325},"2025-12-27",0.0652,{"date":327,"score":318,"percentile":328},"2025-12-28",0.0651,{"date":330,"score":331,"percentile":332},"2025-12-29",0.00023,0.05596,{"date":334,"score":331,"percentile":335},"2025-12-30",0.05583,{"date":337,"score":331,"percentile":338},"2025-12-31",0.05618,{"date":340,"score":331,"percentile":341},"2026-01-01",0.05686,{"date":343,"score":331,"percentile":344},"2026-01-02",0.05681,{"date":346,"score":331,"percentile":347},"2026-01-03",0.05643,{"date":349,"score":331,"percentile":350},"2026-01-04",0.05551,{"date":352,"score":331,"percentile":353},"2026-01-05",0.05513,{"date":355,"score":331,"percentile":356},"2026-01-06",0.0551,{"date":358,"score":331,"percentile":359},"2026-01-07",0.05531,{"date":361,"score":331,"percentile":362},"2026-01-08",0.05592,{"date":364,"score":331,"percentile":365},"2026-01-09",0.0559,{"date":367,"score":331,"percentile":368},"2026-01-10",0.05588,{"date":370,"score":331,"percentile":371},"2026-01-11",0.05577,{"date":373,"score":331,"percentile":374},"2026-01-12",0.05558,{"date":376,"score":331,"percentile":377},"2026-01-13",0.05549,{"date":379,"score":331,"percentile":362},"2026-01-14",{"date":381,"score":331,"percentile":382},"2026-01-15",0.05579,{"date":384,"score":331,"percentile":385},"2026-01-16",0.05582,{"date":387,"score":331,"percentile":368},"2026-01-17",{"date":389,"score":331,"percentile":335},"2026-01-18",{"date":391,"score":331,"percentile":392},"2026-01-19",0.05545,{"date":394,"score":331,"percentile":395},"2026-01-20",0.05519,{"date":397,"score":331,"percentile":395},"2026-01-21",{"date":399,"score":331,"percentile":400},"2026-01-22",0.05501,{"date":402,"score":331,"percentile":374},"2026-01-23",{"date":404,"score":331,"percentile":405},"2026-01-24",0.05603,{"date":407,"score":331,"percentile":408},"2026-01-25",0.05533,{"date":410,"score":331,"percentile":411},"2026-01-26",0.05509,{"date":413,"score":331,"percentile":414},"2026-01-27",0.05489,{"date":416,"score":331,"percentile":417},"2026-01-28",0.05474,{"date":419,"score":331,"percentile":420},"2026-01-29",0.05486,{"date":422,"score":331,"percentile":423},"2026-01-30",0.05483,{"date":425,"score":331,"percentile":426},"2026-01-31",0.05467,{"date":428,"score":331,"percentile":429},"2026-02-01",0.05534,[431],{"source":122,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":432,"cvss_v4_0":9},{"baseScore":4,"baseSeverity":433,"vectorString":123,"impactScore":434,"exploitabilityScore":435},"HIGH",9.8,2.6,[437,466],{"ecosystem":9,"name":438,"vendor":439,"product":439,"cpe_part":440,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":441},"Linux","linux","a",[442,449,452,455,458,461,464],{"version":443,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":447,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C 0e7814b028cd50b3ff79659d23dfa9da6a1e75e1",true,"00cfd77b9063dcdf3628a7087faba60de85a9cc8","including","0e7814b028cd50b3ff79659d23dfa9da6a1e75e1","excluding",{"version":450,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":451,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C 3554482f4691571fc4b5490c17ae26896e62171c","3554482f4691571fc4b5490c17ae26896e62171c",{"version":453,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":454,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C 67409b358500c71632116356a0b065f112d7b707","67409b358500c71632116356a0b065f112d7b707",{"version":456,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":457,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C 6452b162549c7f9ef54655d3fb9977b9192e6e5b","6452b162549c7f9ef54655d3fb9977b9192e6e5b",{"version":459,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":460,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C 12134a652b0a10064844ea235173e70246eba6dc","12134a652b0a10064844ea235173e70246eba6dc",{"version":462,"is_range":444,"range_type":128,"version_start":445,"version_start_type":446,"version_end":463,"version_end_type":448,"fixed_in":9},">= 00cfd77b9063dcdf3628a7087faba60de85a9cc8, \u003C b4cd80b0338945a94972ac3ed54f8338d2da2076","b4cd80b0338945a94972ac3ed54f8338d2da2076",{"version":465,"is_range":117,"range_type":128,"version_start":465,"version_start_type":446,"version_end":465,"version_end_type":446,"fixed_in":9},"5.10",{"ecosystem":9,"name":467,"vendor":439,"product":468,"cpe_part":469,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":470},"linux kernel","linux_kernel","o",[471,475,479,483,485,487,489,491,493,495],{"version":472,"is_range":444,"range_type":473,"version_start":465,"version_start_type":446,"version_end":474,"version_end_type":448,"fixed_in":9},"gte5.10_lt6.1.111","cpe","6.1.111",{"version":476,"is_range":444,"range_type":473,"version_start":477,"version_start_type":446,"version_end":478,"version_end_type":448,"fixed_in":9},"gte6.2_lt6.6.52","6.2","6.6.52",{"version":480,"is_range":444,"range_type":473,"version_start":481,"version_start_type":446,"version_end":482,"version_end_type":448,"fixed_in":9},"gte6.7_lt6.10.11","6.7","6.10.11",{"version":484,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc1",{"version":486,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc2",{"version":488,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc3",{"version":490,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc4",{"version":492,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc5",{"version":494,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc6",{"version":496,"is_range":117,"range_type":473,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.11:rc7"]