Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context while
Impact
When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context while sockets were still pointing at it. If the link comes back and the connection resumes after TCP retransmits, the kernel dereferences the freed context - a use-after-free driven by nothing more exotic than a link flap on a node carrying offloaded TLS connections. This is the offload-to-software fallback seam, and on a cluster fabric link flaps are routine rather than exceptional.
Who can reach it
No attacker privilege on the node is required. Any tenant or platform connection using NIC-offloaded kTLS is enough; the trigger is a netdev down/up transition (link flap, driver reset, ethtool reconfiguration, switch-side event) with live offloaded connections, followed by data resuming after retransmission. A peer on the fabric can help by keeping the connection alive across the flap. Conditional on TLS device offload actually being enabled on the NIC - check ethtool's tls-hw-tx-offload / tls-hw-rx-offload features.
What to do
Boot a kernel carrying the fix commits below (no fixed stable version published; this is old enough that most maintained kernels already carry it - verify rather than assume). Interim control: disable kTLS NIC offload with ethtool (tls-hw-tx-offload off, tls-hw-rx-offload off) so kTLS runs in software and the offload teardown path is never taken.
References
Related entries
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketCVE-2025-37756 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF verdict that grows the scatterlist (bpf_msg_push_data) combined with a cork_bytes settingCVE-2025-38166 · Linux kernel (net/tls)High
- Linux kernel (net/tls): KTLS assumes it owns the TCP receive queue. When another reader drains bytes first, the oldCVE-2025-38616 · Linux kernel (net/tls)High
- Linux kernel (net/tls): The kTLS device-offload setup resolved the socket's netdevice outside RCU, so the net_device itCVE-2025-40149 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A receiver that holds its TCP window at zero keeps the kTLS sender blocked inside tx_lockCVE-2023-54306 · Linux kernel (net/tls)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.