๐Ÿ” CVE Alert

CVE-2026-64422

UNKNOWN 0.0

net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP socket state. The sysctl is stored as an `int` but copied into the `u32` `tp->reordering` field for new sockets, so negative writes wrap to large values. With `tcp_mtu_probing=2`, the wrapped value can overflow the `tcp_mtu_probe()` size calculation and drive the MTU probing path into an out-of-bounds read. Route `tcp_reordering` writes through `proc_dointvec_minmax()` and require it to be at least 1. Also require `tcp_max_reordering` to be at least 1 so the configured maximum cannot become negative either. When registering the table for a non-init network namespace, relocate `extra2` pointers that refer into `init_net.ipv4` so the `tcp_reordering` upper bound follows that namespace's `tcp_max_reordering`. Harden `tcp_mtu_probe()` itself by computing `size_needed` as `u64`. This keeps the send queue and window checks from being bypassed through signed integer overflow.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < f0d88a4cd03affff6c08adf6c63964e235aede43 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < 27ddf4486c7dbf5bdd393fa8bef6b67179796d98 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < 782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < e81f805824a8109504fce090641b17d135b48cd1 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < 99206ce2244f8a3ed64298d0667c9055845a5dc7 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < bbae351c0f32f7c200249e4aa6561b2b419dcf69 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < a094ac95d3b69adfa1676eb9c8eae6835d4f1671 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf < efb8763d7bbb40cff4cc55a6b62c3095a038149c
Linux / Linux
2.6.24

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/f0d88a4cd03affff6c08adf6c63964e235aede43 git.kernel.org: https://git.kernel.org/stable/c/27ddf4486c7dbf5bdd393fa8bef6b67179796d98 git.kernel.org: https://git.kernel.org/stable/c/782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae git.kernel.org: https://git.kernel.org/stable/c/e81f805824a8109504fce090641b17d135b48cd1 git.kernel.org: https://git.kernel.org/stable/c/99206ce2244f8a3ed64298d0667c9055845a5dc7 git.kernel.org: https://git.kernel.org/stable/c/bbae351c0f32f7c200249e4aa6561b2b419dcf69 git.kernel.org: https://git.kernel.org/stable/c/a094ac95d3b69adfa1676eb9c8eae6835d4f1671 git.kernel.org: https://git.kernel.org/stable/c/efb8763d7bbb40cff4cc55a6b62c3095a038149c