Back to overview

CVE-2026-64002

HIGH
7.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl_table() we can be sure no threads can possibly use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.

Metadata

CVE ID
CVE-2026-64002
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 14:56 UTC
Last updated
2026-07-20 13:42 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux 122ff243f5f104194750ecbc76d5946dd1eec934 < ecf45080a4d3f4526cacb8b14060fe3b49a6913b, 122ff243f5f104194750ecbc76d5946dd1eec934 < a0ffc6081a8b27082dd5eae5aa1e3f59bbecf06c, 122ff243f5f104194750ecbc76d5946dd1eec934 < 5b23a2ff379e70b6b9ff744a972b63e1f8f4d996, 122ff243f5f104194750ecbc76d5946dd1eec934 < 8e59d4d0dcde2dfb07a7ef855c849a2a0560aa57 …
Linux Linux 3.16, 0 < 3.16, 5.10.259 ≤ 5.10.*, 5.15.210 ≤ 5.15.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview