CVE-2026-64024
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcptwisn leak enabling ISN prediction
Blamed commit moved the TIME_WAIT-derived ISN from the skb control
block to a per-CPU variable, assuming the value would always be consumed
by tcpconnrequest() for the same packet that wrote it. That assumption
is violated by multiple drop paths between the producer
(_thiscpuwrite(tcptwisn, isn) in tcpv{4,6}_rcv()) and the consumer
(tcpconnrequest()):
- minttl / minhopcount check
- xfrm policy check
- tcpinboundhash() MD5/AO mismatch
- tcpfilter() eBPF/SOATTACH_FILTER drop
- th->syn && th->fin discard in tcprcvstateprocess() TCPLISTEN
- pspskrxpolicycheck() in tcpv{4,6}do_rcv()
- tcpchecksumcomplete() in tcpv{4,6}do_rcv()
- tcpv{4,6}cookie_check() returning NULL
When a packet is dropped on any of these paths, tcptwisn is left set.
The next SYN processed on the same CPU then consumes the non zero value in
tcpconnrequest(), receiving a potentially predictable ISN.
This patch moves back tcptwisn to skb->cb[], getting rid of the per-cpu
variable.
Note that tcpv{4,6}fill_cb() do not set it.
Very litle impact on overall code size/complexity:
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new
add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)
Function old new delta
tcpv6rcv 3038 3042 +4
tcpv4rcv 3035 3039 +4
tcpconnrequest 2938 2923 -15
Total: Before=24436060, After=24436053, chg -0.00%
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://git.kernel.org/stable/c/1bbf0ced1d9db73ac7893c2187f3459288603e0d, https://git.kernel.org/stable/c/4affe063fa56c880cbea8d0bfded0bb80751579d, https://git.kernel.org/stable/c/e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64024.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64024, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git