PT-2026-61341 · Linux+1 · Linux Kernel+1

CVE-2026-64024

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the TCP implementation where a stale per-CPU tcp tw isn variable can leak, enabling Initial Sequence Number (ISN) prediction. The issue occurs because the system assumes the tcp tw isn value written in tcp v4 rcv() or tcp v6 rcv() is always consumed by tcp conn request() for the same packet. However, several drop paths—including min ttl checks, xfrm policy checks, tcp inbound hash() MD5/AO mismatches, tcp filter() eBPF drops, and checksum failures—can cause a packet to be discarded while leaving the tcp tw isn variable set. Consequently, the next SYN packet processed on the same CPU consumes this stale value, leading to a predictable ISN.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64024
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu