Linux Kernel TCP Vulnerability Leading to Socket Reference Errors
CVE-2026-64575
What is CVE-2026-64575?
A vulnerability in the Linux kernel affects the TCP socket management during batch reallocations. Specifically, the function responsible for handling socket references, bpf_iter_tcp_batch(), mismanages the socket references leading to potential kernel panic scenarios. When a realloc operation fails, it erroneously allows dereferencing a cookie rather than a valid socket pointer, resulting in null pointer dereferences and system instability. This vulnerability necessitates immediate attention to prevent service interruptions and maintain system integrity.
Affected Version(s)
Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 9f27c4f0ae35b5390ce4f7a54d3501144e41a54d
Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 8a726e9585ffe7bfbfad2b5279277a00973970f3
Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 980a813452754f8001704744e92f7aa697c53dd3