Out-of-bounds read in Linux kernel - CVE-2026-64422
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in tcp_mtu_probe() when processing an invalid net.ipv4.tcp_reordering value during MTU probing. A local user can write a negative tcp_reordering value to trigger the out-of-bounds read and disclose sensitive information.
Exploitation requires tcp_mtu_probing to be set to 2.
Affected software
openEuler
Ubuntu
bpftool
python3-perf-debuginfo
python3-perf
perf-debuginfo
perf
kernel-tools-devel
kernel-tools-debuginfo
kernel-tools
kernel-source
kernel-headers
kernel-devel
kernel-debugsource
kernel-debuginfo
bpftool-debuginfo
kernel
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64422
bpftool - update to 5.10.0-330.0.0.231
python3-perf-debuginfo - update to 5.10.0-330.0.0.231
python3-perf - update to 5.10.0-330.0.0.231
perf-debuginfo - update to 5.10.0-330.0.0.231
perf - update to 5.10.0-330.0.0.231
kernel-tools-devel - update to 5.10.0-330.0.0.231
kernel-tools-debuginfo - update to 5.10.0-330.0.0.231
kernel-tools - update to 5.10.0-330.0.0.231
kernel-source - update to 5.10.0-330.0.0.231
kernel-headers - update to 5.10.0-330.0.0.231
kernel-devel - update to 5.10.0-330.0.0.231
kernel-debugsource - update to 5.10.0-330.0.0.231
kernel-debuginfo - update to 5.10.0-330.0.0.231
bpftool-debuginfo - update to 5.10.0-330.0.0.231
kernel - update to 5.10.0-330.0.0.231
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/27ddf4486c7dbf5bdd393fa8bef6b67179796d98
- https://git.kernel.org/stable/c/782708ca1ea1f68b8cbb5ea3a7f5f18d0000efae
- https://git.kernel.org/stable/c/99206ce2244f8a3ed64298d0667c9055845a5dc7
- https://git.kernel.org/stable/c/a094ac95d3b69adfa1676eb9c8eae6835d4f1671
- https://git.kernel.org/stable/c/bbae351c0f32f7c200249e4aa6561b2b419dcf69
- https://git.kernel.org/stable/c/e81f805824a8109504fce090641b17d135b48cd1
- https://git.kernel.org/stable/c/efb8763d7bbb40cff4cc55a6b62c3095a038149c
- https://git.kernel.org/stable/c/f0d88a4cd03affff6c08adf6c63964e235aede43