CVE-2026-64024

Source
https://cve.org/CVERecord?id=CVE-2026-64024
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64024.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-64024
Downstream
Published
2026-07-19T15:39:16.598Z
Modified
2026-07-22T03:31:36.302765750Z
Severity
  • 9.4 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H CVSS Calculator
Summary
tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
Details

In the Linux kernel, the following vulnerability has been resolved:

tcp: fix stale per-CPU tcptwisn leak enabling ISN prediction

Blamed commit moved the TIMEWAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcpconn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__thiscpuwrite(tcptwisn, isn) in tcpv{4,6}rcv()) and the consumer (tcpconnrequest()):

  • minttl / minhopcount check
  • xfrm policy check
  • tcpinboundhash() MD5/AO mismatch
  • tcpfilter() eBPF/SOATTACH_FILTER drop
  • th->syn && th->fin discard in tcprcvstateprocess() TCPLISTEN
  • pspskrxpolicycheck() in tcp_v{4,6}dorcv()
  • tcpchecksumcomplete() in tcp_v{4,6}dorcv()
  • tcp_v{4,6}cookiecheck() returning NULL

When a packet is dropped on any of these paths, tcptwisn is left set.

The next SYN processed on the same CPU then consumes the non zero value in tcpconnrequest(), receiving a potentially predictable ISN.

This patch moves back tcptwisn to skb->cb[], getting rid of the per-cpu variable.

Note that tcp_v{4,6}fillcb() do not set it.

Very litle impact on overall code size/complexity:

$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcpv6rcv 3038 3042 +4 tcpv4rcv 3035 3039 +4 tcpconnrequest 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64024.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
41eecbd712b73f0d5dcf1152b9a1c27b1f238028
Fixed
e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd
Fixed
4affe063fa56c880cbea8d0bfded0bb80751579d
Fixed
1bbf0ced1d9db73ac7893c2187f3459288603e0d

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64024.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.10.0
Fixed
6.18.34
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.11

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-64024.json"