In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcptwisn leak enabling ISN prediction
Blamed commit moved the TIMEWAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcpconn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__thiscpuwrite(tcptwisn, isn) in tcpv{4,6}rcv()) and the consumer (tcpconnrequest()):
When a packet is dropped on any of these paths, tcptwisn is left set.
The next SYN processed on the same CPU then consumes the non zero value in tcpconnrequest(), receiving a potentially predictable ISN.
This patch moves back tcptwisn to skb->cb[], getting rid of the per-cpu variable.
Note that tcp_v{4,6}fillcb() do not set it.
Very litle impact on overall code size/complexity:
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcpv6rcv 3038 3042 +4 tcpv4rcv 3035 3039 +4 tcpconnrequest 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64024.json"
}