Answer in brief
CVE-2026-64575 records a High severity (CVSS 7.8) vulnerability in bpf: tcp: fix double sock release on batch realloc. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <9f27c4f0ae35b5390ce4f7a54d3501144e41a54d || >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <8a726e9585ffe7bfbfad2b5279277a00973970f3 || >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <980a813452754f8001704744e92f7aa697c53dd3 | 9f27c4f0ae35b5390ce4f7a54d3501144e41a54d, 8a726e9585ffe7bfbfad2b5279277a00973970f3, 980a813452754f8001704744e92f7aa697c53dd3 |
| Linux/Linuxgeneric | 6.17 | Not reported |
| Linux/Linuxgeneric | >=9794ac757a650dd594391192183c9caf939f8223 <c842882e4c5d2818b858d6baf3fd10958c93f729 || >=1d7a82c1df5fc397eaca9c6b8c8f61aae9866ad4 <7a6a6d2a127866935f87b55b557bc89693065462 || >=36f955807ee4ede07e9410772f792e4cb4ec807b <f0c1810320b0dac228103fad7311e89532134d83 || >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <9f27c4f0ae35b5390ce4f7a54d3501144e41a54d || >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <8a726e9585ffe7bfbfad2b5279277a00973970f3 || >=cdec67a489d4fdae3e83e04fca0419136a83c4c2 <980a813452754f8001704744e92f7aa697c53dd3 | c842882e4c5d2818b858d6baf3fd10958c93f729, 7a6a6d2a127866935f87b55b557bc89693065462, f0c1810320b0dac228103fad7311e89532134d83, 9f27c4f0ae35b5390ce4f7a54d3501144e41a54d, 8a726e9585ffe7bfbfad2b5279277a00973970f3, 980a813452754f8001704744e92f7aa697c53dd3 |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 19, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk < end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock. Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release. BUG: KASAN: null-ptr-deref in __sock_gen_cookie Read of size 8 at addr 0000000000000059 by task exploit ... __sock_gen_cookie (net/core/sock_diag.c:28) bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918) bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270) bpf_seq_read (kernel/bpf/bpf_iter.c:205) vfs_read (fs/read_write.c:572) ksys_read (fs/read_write.c:716) do_syscall_64 entry_SYSCALL_64_after_hwframe Kernel panic - not syncing: Fatal exception
Quoted source text, attributed separately from HOL analysis.