PT-2026-61341 · Linux · Linux
CVE-2026-64024
·
Published
2026-07-19
·
Updated
2026-07-19
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H |
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcp tw isn leak enabling ISN prediction
Blamed commit moved the TIME WAIT-derived ISN from the skb control
block to a per-CPU variable, assuming the value would always be consumed
by tcp conn request() for the same packet that wrote it. That assumption
is violated by multiple drop paths between the producer
( this cpu write(tcp tw isn, isn) in tcp v{4,6} rcv()) and the consumer
(tcp conn request()):
- min ttl / min hopcount check
- xfrm policy check
- tcp inbound hash() MD5/AO mismatch
- tcp filter() eBPF/SO ATTACH FILTER drop
- th->syn && th->fin discard in tcp rcv state process() TCP LISTEN
- psp sk rx policy check() in tcp v{4,6} do rcv()
- tcp checksum complete() in tcp v{4,6} do rcv()
- tcp v{4,6} cookie check() returning NULL
When a packet is dropped on any of these paths, tcp tw isn is left set.
The next SYN processed on the same CPU then consumes the non zero value in
tcp conn request(), receiving a potentially predictable ISN.
This patch moves back tcp tw isn to skb->cb[], getting rid of the per-cpu
variable.
Note that tcp v{4,6} fill cb() do not set it.
Very litle impact on overall code size/complexity:
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new
add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)
Function old new delta
tcp v6 rcv 3038 3042 +4
tcp v4 rcv 3035 3039 +4
tcp conn request 2938 2923 -15
Total: Before=24436060, After=24436053, chg -0.00%
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux