In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after… (CVE-2026-64002)
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl_table() we can be sure no threads can possibly use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.
AI Analysis
Technical Summary
The Linux kernel contained a vulnerability where the ipv4_sysctl_exit_net() function freed net->ipv4.sysctl_local_reserved_ports prematurely, before unregister_net_sysctl_table() completed. This premature freeing could allow threads to access freed memory via sysctls such as /proc/sys/net/ipv4/ip_local_reserved_ports, leading to potential instability or security issues. The fix ensures that net->ipv4.sysctl_local_reserved_ports is freed only after unregister_net_sysctl_table() confirms no threads can use the sysctls.
Potential Impact
The vulnerability could lead to use-after-free conditions in the kernel's IPv4 sysctl handling, potentially causing system instability or enabling an attacker to exploit memory corruption. However, no known exploits in the wild have been reported. The exact impact depends on the ability to trigger concurrent access to freed memory in the kernel.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this issue by adjusting the timing of freeing net->ipv4.sysctl_local_reserved_ports. Since no patch links or vendor advisories are provided, users should monitor official Linux kernel releases and update to the fixed version when available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after… (CVE-2026-64002)
Description
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl_table() we can be sure no threads can possibly use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel contained a vulnerability where the ipv4_sysctl_exit_net() function freed net->ipv4.sysctl_local_reserved_ports prematurely, before unregister_net_sysctl_table() completed. This premature freeing could allow threads to access freed memory via sysctls such as /proc/sys/net/ipv4/ip_local_reserved_ports, leading to potential instability or security issues. The fix ensures that net->ipv4.sysctl_local_reserved_ports is freed only after unregister_net_sysctl_table() confirms no threads can use the sysctls.
Potential Impact
The vulnerability could lead to use-after-free conditions in the kernel's IPv4 sysctl handling, potentially causing system instability or enabling an attacker to exploit memory corruption. However, no known exploits in the wild have been reported. The exact impact depends on the ability to trigger concurrent access to freed memory in the kernel.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to address this issue by adjusting the timing of freeing net->ipv4.sysctl_local_reserved_ports. Since no patch links or vendor advisories are provided, users should monitor official Linux kernel releases and update to the fixed version when available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-gghq-r38g-rg55
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64002"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27aa2a4a8d598912d889
Added to database: 07/19/2026, 19:38:18 UTC
Last enriched: 07/19/2026, 19:59:30 UTC
Last updated: 07/20/2026, 21:51:25 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.