In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit… (CVE-2026-64024)
In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcp_conn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer (tcp_conn_request()): - min_ttl / min_hopcount check - xfrm policy check - tcp_inbound_hash() MD5/AO mismatch - tcp_filter() eBPF/SO_ATTACH_FILTER drop - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv() - tcp_checksum_complete() in tcp_v{4,6}_do_rcv() - tcp_v{4,6}_cookie_check() returning NULL When a packet is dropped on any of these paths, tcp_tw_isn is left set. The next SYN processed on the same CPU then consumes the non zero value in tcp_conn_request(), receiving a potentially predictable ISN. This patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu variable. Note that tcp_v{4,6}_fill_cb() do not set it. Very litle impact on overall code size/complexity: $ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcp_v6_rcv 3038 3042 +4 tcp_v4_rcv 3035 3039 +4 tcp_conn_request 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%
AI Analysis
Technical Summary
The Linux kernel TCP vulnerability (CVE-2026-64024) involved a stale per-CPU tcp_tw_isn variable that was not cleared when packets were dropped on various paths, such as TTL/hopcount checks, security policy checks, checksum failures, and others. This stale value could be consumed by the next SYN packet processed on the same CPU, potentially allowing an attacker to predict the ISN. The fix reverted the ISN storage from a per-CPU variable back to the skb control block, preventing stale ISN reuse. The patch had minimal impact on code size and complexity.
Potential Impact
The vulnerability could enable an attacker to predict TCP Initial Sequence Numbers, which may weaken TCP connection security by facilitating certain types of spoofing or session hijacking attacks. However, no known exploits in the wild have been reported. The impact is limited to TCP ISN predictability due to stale state leakage in the kernel's TCP stack.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by moving the tcp_tw_isn variable from a per-CPU variable back to the packet control block to prevent stale ISN reuse. Users should apply the official Linux kernel updates that include this patch once available. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory for current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit… (CVE-2026-64024)
Description
In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcp_conn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer (tcp_conn_request()): - min_ttl / min_hopcount check - xfrm policy check - tcp_inbound_hash() MD5/AO mismatch - tcp_filter() eBPF/SO_ATTACH_FILTER drop - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv() - tcp_checksum_complete() in tcp_v{4,6}_do_rcv() - tcp_v{4,6}_cookie_check() returning NULL When a packet is dropped on any of these paths, tcp_tw_isn is left set. The next SYN processed on the same CPU then consumes the non zero value in tcp_conn_request(), receiving a potentially predictable ISN. This patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu variable. Note that tcp_v{4,6}_fill_cb() do not set it. Very litle impact on overall code size/complexity: $ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcp_v6_rcv 3038 3042 +4 tcp_v4_rcv 3035 3039 +4 tcp_conn_request 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%
CVSS v3.1
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel TCP vulnerability (CVE-2026-64024) involved a stale per-CPU tcp_tw_isn variable that was not cleared when packets were dropped on various paths, such as TTL/hopcount checks, security policy checks, checksum failures, and others. This stale value could be consumed by the next SYN packet processed on the same CPU, potentially allowing an attacker to predict the ISN. The fix reverted the ISN storage from a per-CPU variable back to the skb control block, preventing stale ISN reuse. The patch had minimal impact on code size and complexity.
Potential Impact
The vulnerability could enable an attacker to predict TCP Initial Sequence Numbers, which may weaken TCP connection security by facilitating certain types of spoofing or session hijacking attacks. However, no known exploits in the wild have been reported. The impact is limited to TCP ISN predictability due to stale state leakage in the kernel's TCP stack.
Mitigation Recommendations
A fix for this vulnerability has been implemented in the Linux kernel by moving the tcp_tw_isn variable from a per-CPU variable back to the packet control block to prevent stale ISN reuse. Users should apply the official Linux kernel updates that include this patch once available. Patch status is not explicitly confirmed in the provided data; therefore, check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-h337-654q-329c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64024"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a5d27a92a4a8d598912cbb5
Added to database: 07/19/2026, 19:38:17 UTC
Last enriched: 07/19/2026, 19:55:19 UTC
Last updated: 07/20/2026, 19:41:22 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.