๐Ÿ” CVE Alert

CVE-2026-64518

UNKNOWN 0.0

tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key().

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). lockdep_sock_is_held() was added in tcp_ao_established_key() by the cited commit. It can be called from tcp_v[46]_timewait_ack() with twsk. Since it does not have sk->sk_lock, the lockdep annotation results in out-of-bound access. $ pahole -C tcp_timewait_sock vmlinux | grep size /* size: 288, cachelines: 5, members: 8 */ $ pahole -C sock vmlinux | grep sk_lock socket_lock_t sk_lock; /* 440 192 */ Let's not use lockdep_sock_is_held() for TCP_TIME_WAIT.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
051f49d5176613dea88ecf73a101c3a99f4720e9 < 87bb3e719042f0030a6dad39118c6a6b2a491ad9 6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6 < 510db031ba6eb40134f84c90ef963ea4b6dfb878 6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6 < 29cf64d128c94cf98d1c69d8b2962d39db5ff4c6 6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6 < 03cb001ef87b3f8d859cf7f96329acf3d6235d29 6.12.5 < 6.12.92
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/87bb3e719042f0030a6dad39118c6a6b2a491ad9 git.kernel.org: https://git.kernel.org/stable/c/510db031ba6eb40134f84c90ef963ea4b6dfb878 git.kernel.org: https://git.kernel.org/stable/c/29cf64d128c94cf98d1c69d8b2962d39db5ff4c6 git.kernel.org: https://git.kernel.org/stable/c/03cb001ef87b3f8d859cf7f96329acf3d6235d29