7.1

CVE-2026-64422

net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes

In the Linux kernel, the following vulnerability has been resolved:

net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes

Reject invalid `net.ipv4.tcp_reordering` values before they reach TCP
socket state. The sysctl is stored as an `int` but copied into the
`u32` `tp->reordering` field for new sockets, so negative writes wrap
to large values.

With `tcp_mtu_probing=2`, the wrapped value can overflow the
`tcp_mtu_probe()` size calculation and drive the MTU probing path into
an out-of-bounds read. Route `tcp_reordering` writes through
`proc_dointvec_minmax()` and require it to be at least 1. Also require
`tcp_max_reordering` to be at least 1 so the configured maximum cannot
become negative either.

When registering the table for a non-init network namespace, relocate
`extra2` pointers that refer into `init_net.ipv4` so the
`tcp_reordering` upper bound follows that namespace's
`tcp_max_reordering`.

Harden `tcp_mtu_probe()` itself by computing `size_needed` as `u64`.
This keeps the send queue and window checks from being bypassed through
signed integer overflow.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < f0d88a4cd03affff6c08adf6c63964e235aede43
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < 27ddf4486c7dbf5bdd393fa8bef6b67179796d98
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < 782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < e81f805824a8109504fce090641b17d135b48cd1
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < 99206ce2244f8a3ed64298d0667c9055845a5dc7
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < bbae351c0f32f7c200249e4aa6561b2b419dcf69
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < a094ac95d3b69adfa1676eb9c8eae6835d4f1671
Status affected
Version 91cc17c0e5e5ada156a8d5787a2509d263ea6bbf
Version < efb8763d7bbb40cff4cc55a6b62c3095a038149c
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 2.6.24
Status affected
Version 0
Version < 2.6.24
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.96
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f0d88a4cd03affff6c08adf6c63964e235aede43
https://git.kernel.org/stable/c/27ddf4486c7dbf5bdd393fa8bef6b67179796d98
https://git.kernel.org/stable/c/782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae
https://git.kernel.org/stable/c/e81f805824a8109504fce090641b17d135b48cd1
https://git.kernel.org/stable/c/99206ce2244f8a3ed64298d0667c9055845a5dc7
https://git.kernel.org/stable/c/bbae351c0f32f7c200249e4aa6561b2b419dcf69
https://git.kernel.org/stable/c/a094ac95d3b69adfa1676eb9c8eae6835d4f1671
https://git.kernel.org/stable/c/efb8763d7bbb40cff4cc55a6b62c3095a038149c