{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.6-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  bpf: tcp: fix double sock release on batch realloc  bpf_iter_tcp_batch() releases the current batch via bpf_iter_tcp_put_batch(), which drops the socket refs and rewrites each slot with the socket cookie, then grows the batch. cur_sk/end_sk are kept for bpf_iter_tcp_resume(), but on realloc failure the function returns ERR_PTR() before resume runs, leaving cur_sk \u003c end_sk over slots that now hold cookies rather than sock pointers. bpf_iter_tcp_seq_stop() then calls bpf_iter_tcp_put_batch() again and dereferences a cookie as a struct sock.  Empty the batch on the failure path so stop() does not release it again. The sockets were already freed by the first bpf_iter_tcp_put_batch(), so nothing leaks, and a later read() rescans the bucket from the start instead of skipping it. The sibling GFP_NOWAIT failure path still holds real socket references and is left for stop() to release.    BUG: KASAN: null-ptr-deref in __sock_gen_cookie   Read of size 8 at addr 0000000000000059 by task exploit    ...    __sock_gen_cookie (net/core/sock_diag.c:28)    bpf_iter_tcp_put_batch (net/ipv4/tcp_ipv4.c:2918)    bpf_iter_tcp_seq_stop (net/ipv4/tcp_ipv4.c:3270)    bpf_seq_read (kernel/bpf/bpf_iter.c:205)    vfs_read (fs/read_write.c:572)    ksys_read (fs/read_write.c:716)    do_syscall_64    entry_SYSCALL_64_after_hwframe   Kernel panic - not syncing: Fatal exception",
  "id": "DEBIAN-CVE-2026-64575",
  "modified": "2026-09-14T16:47:50.487732618Z",
  "published": "2026-08-05T08:16:37.363Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64575"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ],
  "upstream": [
    "CVE-2026-64575"
  ]
}