Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completion
Impact
The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completion, so everything the callback touches afterwards is already-freed socket and context memory. A peer that times its records against a closing socket gets a use-after-free on the node.
Who can reach it
Remote plus a local close: the peer supplies records to a kTLS socket while the owning process closes or returns from the syscall - a normal pattern for short-lived tenant connections, and one an attacker can encourage by resetting connections. No privilege or device node needed; requires an async-capable AEAD driver.
What to do
Boot a kernel carrying the linked stable commits, along with the rest of the tls async-decrypt series. Interim: disable async crypto offload for kTLS.
References
Related entries
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCVE-2024-26584 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCVE-2024-26585 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releasesCVE-2024-26800 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCVE-2025-38471 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): A zero-length record already sitting on the rx_list breaks the invariant that zero-copy decryptCVE-2025-39682 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.