Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives the
Impact
Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives the splice EOF path into the BPF-only 'split record' branch and then into record merging, which assumes a populated buffer - a NULL dereference and kernel oops in the transmit path.
Who can reach it
Local and unprivileged: any process with a kTLS socket calling sendfile()/splice() after a send that bailed out and trimmed both buffers. Every tenant container reaches this with ordinary syscalls - no device node, no capability, no cooperating peer. On kernels with panic_on_oops this is a tenant-triggerable node kill.
What to do
Boot a kernel carrying the linked stable commits. Interim: none at the tenant boundary; review panic_on_oops policy, since it converts a task oops into a full-node outage here.
References
Related entries
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistCVE-2024-35841 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Tls_init published the new sk_prot before the TLS context was fully initialized, so aCVE-2024-36489 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): KTLS stored a negative errno into the socket error field where a positive value is expected. ACVE-2021-47496 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCVE-2022-49094 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, soCVE-2024-26582 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.