Junglewise Threat Intelligence

CVE-2026-64002: Linux Kernel use-after-free in IPv4 sysctl cleanup

CVE-2026-64002 · Severity: info · CVSS 4.7 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking component that could lead to system instability. The issue occurs when the system cleans up network settings, potentially allowing the computer to crash or behave unpredictably if certain internal data is accessed while it is being deleted. This primarily affects systems using network namespaces, a common feature in containerized environments.

Technical details

A use-after-free vulnerability exists in net/ipv4/sysctl_net_ipv4.c within the Linux kernel. The function ipv4_sysctl_exit_net() frees 'net->ipv4.sysctl_local_reserved_ports' before calling unregister_net_sysctl_table(). This creates a race condition where other threads or processes accessing /proc/sys/net/ipv4/ip_local_reserved_ports may attempt to use the memory after it has been deallocated. An attacker with local access could potentially exploit this to cause a kernel panic (denial of service). The issue has been resolved in various stable branches by reordering the cleanup sequence to ensure the sysctl table is unregistered before the associated memory is freed.

Affected products

  • Linux Linux Kernel 3.16 to 6.10.y

Timeline

  • 2026-05-21: disclosed: Initial patch submitted by Eric Dumazet
  • 2026-07-19: advisory: CVE-2026-64002 published in NVD

References

Related threats