Out-of-Bounds Access in Linux Kernel TCP Implementation
CVE-2026-64518

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64518?

A vulnerability was identified in the Linux kernel's TCP implementation related to improper handling of socket locks during the state transition of TCP connections. The tcp_ao_established_key() function lacked proper locking mechanisms, which led to potential out-of-bounds access when called from the tcp_v[46]_timewait_ack() function. This vulnerability could compromise the stability and security of network communications if exploited, making it essential for users to update their systems to the latest version where this issue has been addressed.

Affected Version(s)

Linux 051f49d5176613dea88ecf73a101c3a99f4720e9 < 87bb3e719042f0030a6dad39118c6a6b2a491ad9

Linux 6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6 < 510db031ba6eb40134f84c90ef963ea4b6dfb878

Linux 6b2d11e2d8fc130df4708be0b6b53fd3e6b54cf6 < 29cf64d128c94cf98d1c69d8b2962d39db5ff4c6

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.