Linux Kernel TCP Vulnerability Leading to Socket Reference Errors
CVE-2026-64575

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-64575?

A vulnerability in the Linux kernel affects the TCP socket management during batch reallocations. Specifically, the function responsible for handling socket references, bpf_iter_tcp_batch(), mismanages the socket references leading to potential kernel panic scenarios. When a realloc operation fails, it erroneously allows dereferencing a cookie rather than a valid socket pointer, resulting in null pointer dereferences and system instability. This vulnerability necessitates immediate attention to prevent service interruptions and maintain system integrity.

Affected Version(s)

Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 9f27c4f0ae35b5390ce4f7a54d3501144e41a54d

Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 8a726e9585ffe7bfbfad2b5279277a00973970f3

Linux cdec67a489d4fdae3e83e04fca0419136a83c4c2 < 980a813452754f8001704744e92f7aa697c53dd3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.