CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable
In the Linux kernel, the following vulnerability has been resolved:
netfilter: synproxy: refresh tcphdr after skbensurewritable
synproxytstampadjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inetprotocsumreplace4() on the caller-supplied tcphdr pointer. Both ipv4synproxyhook() and ipv6synproxyhook() obtain that pointer with skbheaderpointer() before calling in, so it may either alias skb->head directly or point at the caller's on-stack tcph buffer.
Between obtaining the pointer and using it, the function calls skbensurewritable(skb, optend), which on a cloned or non-linear skb invokes pskbexpandhead() and frees the old skb->head. After that point the cached th is stale:
caller (ipv[46]synproxyhook) th = skbheaderpointer(skb, ..., &tcph) synproxytstampadjust(skb, protoff, th, ...) skbensurewritable(skb, optend) pskbexpandhead() / kfree(old skb->head) / ... inetprotocsumreplace4(&th->check, ...) / writes into freed head, or into the caller's stack copy leaving the on-wire checksum stale /
The option bytes are written through skb->data and are fine; only the checksum update goes through th and so lands in the wrong place. The result is either a write into freed slab memory or a packet leaving with a checksum that does not match its payload.
Fix by re-deriving th from skb->data + protoff immediately after skbensurewritable() succeeds, so the subsequent checksum update targets the linear, writable header.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64007?
CVE-2026-64007 is classified with a risk rating of 37, indicating a notable vulnerability in the Linux kernel.
How do I fix CVE-2026-64007?
To remediate CVE-2026-64007, update your Linux kernel to the latest version that includes the patch for this vulnerability.
What type of vulnerability is CVE-2026-64007?
CVE-2026-64007 is a netfilter vulnerability related to the synproxy feature in the Linux kernel.
What systems are affected by CVE-2026-64007?
The vulnerability CVE-2026-64007 affects systems running affected versions of the Linux kernel.
When was CVE-2026-64007 published?
CVE-2026-64007 was published on July 19, 2026.