{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64024","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T07:54:57.027Z","datePublished":"2026-07-19T15:39:16.598Z","dateUpdated":"2026-08-05T12:38:18.798Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:38:18.798Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction\n\nBlamed commit moved the TIME_WAIT-derived ISN from the skb control\nblock to a per-CPU variable, assuming the value would always be consumed\nby tcp_conn_request() for the same packet that wrote it. That assumption\nis violated by multiple drop paths between the producer\n(__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer\n(tcp_conn_request()):\n\n - min_ttl / min_hopcount check\n - xfrm policy check\n - tcp_inbound_hash() MD5/AO mismatch\n - tcp_filter() eBPF/SO_ATTACH_FILTER drop\n - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN\n - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv()\n - tcp_checksum_complete() in tcp_v{4,6}_do_rcv()\n - tcp_v{4,6}_cookie_check() returning NULL\n\nWhen a packet is dropped on any of these paths, tcp_tw_isn is left set.\n\nThe next SYN processed on the same CPU then consumes the non zero value in\ntcp_conn_request(), receiving a potentially predictable ISN.\n\nThis patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu\nvariable.\n\nNote that tcp_v{4,6}_fill_cb() do not set it.\n\nVery litle impact on overall code size/complexity:\n\n$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new\nadd/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)\nFunction                                     old     new   delta\ntcp_v6_rcv                                  3038    3042      +4\ntcp_v4_rcv                                  3035    3039      +4\ntcp_conn_request                            2938    2923     -15\nTotal: Before=24436060, After=24436053, chg -0.00%"}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H","baseScore":9.4,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - The vulnerable code is reached from the standard IPv4/IPv6 TCP receive path (tcp_v4_rcv/tcp_v6_rcv) when remote attackers send crafted TCP packets to any listening service on the host.\nAC:L - An attacker fully controls the trigger sequence—establishing TIME_WAIT state, deliberately causing drops on documented paths (e.g., SYN+FIN or checksum failure), and spraying SYNs to land on the same CPU via RPS flow hashing—without depending on uncontrollable timing or memory layout.\nPR:N - Exploitation requires only the ability to send TCP packets to a reachable port; no local shell access, capabilities, or authentication is needed on the target system.\nUI:N - No victim user action is required; the attack is conducted entirely by sending network packets to an internet-facing or LAN-reachable server.\nS:U - Impact is confined to the kernel TCP stack on the target host (predictable ISNs, syncookie bypass, session manipulation) and does not cross a VM, container, or IOMMU security boundary.\nC:L - Stale TIME_WAIT ISNs leak predictable sequence-number information that an off-path attacker can use to infer or intercept data on affected TCP connections, bypassing the cryptographically generated ISNs from secure_tcp_seq_and_ts_off().\nI:H - Predictable server ISNs enable TCP session hijacking and injection of forged segments into established or newly accepted connections, plus syncookie bypass allows unauthorized connection state to be created under flood conditions.\nA:H - Skipping syncookie and SYN-backlog protections when a stale non-zero ISN is consumed allows unauthenticated resource exhaustion and connection-disruption attacks against listening services."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/tcp.h","net/ipv4/tcp.c","net/ipv4/tcp_input.c","net/ipv4/tcp_ipv4.c","net/ipv6/tcp_ipv6.c"],"versions":[{"version":"41eecbd712b73f0d5dcf1152b9a1c27b1f238028","lessThan":"e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd","status":"affected","versionType":"git"},{"version":"41eecbd712b73f0d5dcf1152b9a1c27b1f238028","lessThan":"4affe063fa56c880cbea8d0bfded0bb80751579d","status":"affected","versionType":"git"},{"version":"41eecbd712b73f0d5dcf1152b9a1c27b1f238028","lessThan":"1bbf0ced1d9db73ac7893c2187f3459288603e0d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["include/net/tcp.h","net/ipv4/tcp.c","net/ipv4/tcp_input.c","net/ipv4/tcp_ipv4.c","net/ipv6/tcp_ipv6.c"],"versions":[{"version":"6.10","status":"affected"},{"version":"0","lessThan":"6.10","status":"unaffected","versionType":"semver"},{"version":"6.18.34","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.11","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"6.18.34"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.0.11"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.10","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd"},{"url":"https://git.kernel.org/stable/c/4affe063fa56c880cbea8d0bfded0bb80751579d"},{"url":"https://git.kernel.org/stable/c/1bbf0ced1d9db73ac7893c2187f3459288603e0d"}],"title":"tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction","x_generator":{"engine":"bippy-1.2.0"}}}}