Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, so
Impact
The async decrypt completion released pages that the decrypt path never took a reference on, so a partially-read record left the receive list pointing at freed pages. The next read walks freed memory - a network-driven use-after-free in the kTLS receive path.
Who can reach it
Remote: a peer sends records to a kTLS RX socket while the local reader does partial reads (a short recv() buffer is enough). Any kTLS connection on the node qualifies; no local privilege or device node required. Async decrypt must be in play, i.e. an async-capable AEAD driver such as cryptd-backed AES-NI.
What to do
Boot a kernel carrying the linked stable commits, along with the rest of the tls async-decrypt series. Interim: disable async crypto offload for kTLS.
References
Related entries
- Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completionCVE-2024-26583 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCVE-2024-26584 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCVE-2024-26585 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releasesCVE-2024-26800 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCVE-2025-38471 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.