Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releases
Impact
When a decrypt goes to the crypto backlog and a sibling decrypt fails, the error path releases pages that the async callback has already freed. That is a double free of record pages in the kTLS receive path, reachable from the network.
Who can reach it
Remote records plus a saturated crypto queue, which a co-tenant running heavy encrypted I/O on the same node produces. Any kTLS RX socket qualifies; no local privilege or device node. Requires a backlog-capable async AEAD (cryptd/AES-NI).
What to do
Update to 6.6.21 / 6.7.9 or later, or a kernel carrying the linked stable commits. Interim: disable async crypto offload for kTLS.
References
Related entries
- Linux kernel (net/tls): The synchronous decrypt path shared refcounting and completion state with the async path, so aCVE-2024-58240 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The strparser kept a stale reference to an skb that TCP had already coalesced away, and theCVE-2025-38471 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): A zero-length record already sitting on the rx_list breaks the invariant that zero-copy decryptCVE-2025-39682 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the socket buffer is too small to hold a whole record, kTLS parses early and re-parses asCVE-2025-39946 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLSCVE-2025-40176 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): Closing a kTLS socket cancelled the transmit work item, but the write-space callback couldCVE-2026-23240 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.