Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and the
Impact
When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and the async callback fires twice. kTLS treated that as an error and unwound buffers the callback still owns, giving a double-release of record memory on a node under crypto load.
Who can reach it
Remote peers supply the record volume; the trigger is a saturated cryptd queue, which a co-tenant driving heavy kTLS or dm-crypt traffic produces on the same node. Any kTLS socket is in scope, no privilege needed. Requires a backlog-capable async AEAD (cryptd/AES-NI).
What to do
Boot a kernel carrying the linked stable commits, along with the rest of the tls async-decrypt series. Interim: disable async crypto offload for kTLS, or raise cryptd queue limits so the backlog path is not hit.
References
Related entries
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCVE-2024-26585 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releasesCVE-2024-26800 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCVE-2025-38471 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): A zero-length record already sitting on the rx_list breaks the invariant that zero-copy decryptCVE-2025-39682 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the socket buffer is too small to hold a whole record, kTLS parses early and re-parses asCVE-2025-39946 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.