PT-2026-61341 · Linux · Linux

CVE-2026-64024

·

Publicado

2026-07-19

·

Atualizado

2026-07-19

CVSS v3.1

9.4

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcp tw isn leak enabling ISN prediction
Blamed commit moved the TIME WAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcp conn request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer ( this cpu write(tcp tw isn, isn) in tcp v{4,6} rcv()) and the consumer (tcp conn request()):
  • min ttl / min hopcount check
  • xfrm policy check
  • tcp inbound hash() MD5/AO mismatch
  • tcp filter() eBPF/SO ATTACH FILTER drop
  • th->syn && th->fin discard in tcp rcv state process() TCP LISTEN
  • psp sk rx policy check() in tcp v{4,6} do rcv()
  • tcp checksum complete() in tcp v{4,6} do rcv()
  • tcp v{4,6} cookie check() returning NULL
When a packet is dropped on any of these paths, tcp tw isn is left set.
The next SYN processed on the same CPU then consumes the non zero value in tcp conn request(), receiving a potentially predictable ISN.
This patch moves back tcp tw isn to skb->cb[], getting rid of the per-cpu variable.
Note that tcp v{4,6} fill cb() do not set it.
Very litle impact on overall code size/complexity:
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcp v6 rcv 3038 3042 +4 tcp v4 rcv 3035 3039 +4 tcp conn request 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-64024

Produtos afetados

Linux