CVE-2026-64024
In the Linux kernel, the following vulnerability has been resolved:
tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
Blamed commit moved the TIME_WAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcp_conn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer (tcp_conn_request()):
- min_ttl / min_hopcount check - xfrm policy check - tcp_inbound_hash() MD5/AO mismatch - tcp_filter() eBPF/SO_ATTACH_FILTER drop - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv() - tcp_checksum_complete() in tcp_v{4,6}_do_rcv() - tcp_v{4,6}_cookie_check() returning NULL
Leer descripción completaMostrar menos
When a packet is dropped on any of these paths, tcp_tw_isn is left set.
The next SYN processed on the same CPU then consumes the non zero value in tcp_conn_request(), receiving a potentially predictable ISN.
This patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu variable.
Note that tcp_v{4,6}_fill_cb() do not set it.
Very litle impact on overall code size/complexity:
$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcp_v6_rcv 3038 3042 +4 tcp_v4_rcv 3035 3039 +4 tcp_conn_request 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
- Puntuación base: 9.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.39%
- Percentil entre todas las CVEs puntuadas: 30
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access45 %
Vulnerabilidad de red en kernel Linux sin requerimientos de autenticación (PR:N, UI:N). Permite predicción de ISN en TCP, afectando confidencialidad e integridad. Sin contexto explícito de ejecución remota confirmada.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-64024",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.4,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 5.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "41eecbd712b73f0d5dcf1152b9a1c27b1f238028",
"lessThan": "e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd",
"versionType": "git"
},
{
"status": "affected",
"version": "41eecbd712b73f0d5dcf1152b9a1c27b1f238028",
"lessThan": "4affe063fa56c880cbea8d0bfded0bb80751579d",
"versionType": "git"
},
{
"status": "affected",
"version": "41eecbd712b73f0d5dcf1152b9a1c27b1f238028",
"lessThan": "1bbf0ced1d9db73ac7893c2187f3459288603e0d",
"versionType": "git"
}
],
"programFiles": [
"include/net/tcp.h",
"net/ipv4/tcp.c",
"net/ipv4/tcp_input.c",
"net/ipv4/tcp_ipv4.c",
"net/ipv6/tcp_ipv6.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.18.34",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.0.11",
"versionType": "semver",
"lessThanOrEqual": "7.0.*"
},
{
"status": "unaffected",
"version": "7.1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"include/net/tcp.h",
"net/ipv4/tcp.c",
"net/ipv4/tcp_input.c",
"net/ipv4/tcp_ipv4.c",
"net/ipv6/tcp_ipv6.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-19T16:17:42.413",
"references": [
{
"url": "https://git.kernel.org/stable/c/1bbf0ced1d9db73ac7893c2187f3459288603e0d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4affe063fa56c880cbea8d0bfded0bb80751579d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/e47f7060eaf60894e3e4d0e3c4fe6e1f2eacfbdd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Awaiting Analysis",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction\n\nBlamed commit moved the TIME_WAIT-derived ISN from the skb control\nblock to a per-CPU variable, assuming the value would always be consumed\nby tcp_conn_request() for the same packet that wrote it. That assumption\nis violated by multiple drop paths between the producer\n(__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer\n(tcp_conn_request()):\n\n - min_ttl / min_hopcount check\n - xfrm policy check\n - tcp_inbound_hash() MD5/AO mismatch\n - tcp_filter() eBPF/SO_ATTACH_FILTER drop\n - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN\n - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv()\n - tcp_checksum_complete() in tcp_v{4,6}_do_rcv()\n - tcp_v{4,6}_cookie_check() returning NULL\n\nWhen a packet is dropped on any of these paths, tcp_tw_isn is left set.\n\nThe next SYN processed on the same CPU then consumes the non zero value in\ntcp_conn_request(), receiving a potentially predictable ISN.\n\nThis patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu\nvariable.\n\nNote that tcp_v{4,6}_fill_cb() do not set it.\n\nVery litle impact on overall code size/complexity:\n\n$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new\nadd/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)\nFunction old new delta\ntcp_v6_rcv 3038 3042 +4\ntcp_v4_rcv 3035 3039 +4\ntcp_conn_request 2938 2923 -15\nTotal: Before=24436060, After=24436053, chg -0.00%"
}
],
"lastModified": "2026-07-30T14:59:47.950",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}