CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64422

highCVSS 7.1covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes Reject invalid net.ipv4.tcp_reordering values before they reach TCP socket state. The sysctl is stored as an int but copied into the u32 tp->reordering field for new sockets, so negative writes wrap to large values. With tcp_mtu_probing=2, the wrapped value can overflow the tcp_mtu_probe() size calculation and drive the MTU probing path into an out-of-bounds read. Route tcp_reordering writes through proc_dointvec_minmax() and require it to be at least 1. Also require tcp_max_reordering to be at least 1 so the configured maximum cannot become negative either. When registering the table for a non-init network namespace, relocate extra2 pointers that refer into init_net.ipv4 so the tcp_reordering upper bound follows that namespace's tcp_max_reordering. Harden tcp_mtu_probe() itself by computing size_needed as u64. This keeps the send queue and window checks from being bypassed through signed integer overflow.

CSIRTS triage

What
There is a vulnerability related to TCP reordering sysctl writes and MTU probe sizes.
Who is affected
Deployments of the Linux kernel that utilize TCP settings.
Urgency
Remediation is important to ensure network stability, with no known exploits currently.
Action
Update to the latest kernel version that includes the fix.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64422

Get an email if CVE-2026-64422 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64422

CVE.org record

Embed the live status

CVE-2026-64422 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64422 status](https://www.csirts.com/badge/CVE-2026-64422)](https://www.csirts.com/cve/CVE-2026-64422)