DEBIAN-CVE-2026-64007
In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skbensurewritable synproxytstampadjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inetprotocsumreplace4() on the caller-supplied tcphdr pointer. Both ipv4synproxyhook() and ipv6synproxyhook() obtain that pointer with skbheaderpointer() before calling in, so it may either alias skb->head directly or point at the caller's on-stack tcph buffer. Between obtaining the pointer and using it, the function calls skbensurewritable(skb, optend), which on a cloned or non-linear skb invokes pskbexpandhead() and frees the old skb->head. After that point the cached th is stale: caller (ipv[46]synproxyhook) th = skbheaderpointer(skb, ..., &tcph) synproxytstampadjust(skb, protoff, th, ...) skbensurewritable(skb, optend) pskbexpandhead() / kfree(old skb->head) / ... inetprotocsumreplace4(&th->check, ...) / writes into freed head, or into the caller's stack copy leaving the on-wire checksum stale / The option bytes are written through skb->data and are fine; only the checksum update goes through th and so lands in the wrong place. The result is either a write into freed slab memory or a packet leaving with a checksum that does not match its payload. Fix by re-deriving th from skb->data + protoff immediately after skbensurewritable() succeeds, so the subsequent checksum update targets the linear, writable header.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://security-tracker.debian.org/tracker/CVE-2026-64007