Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns without
Impact
Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns without dropping it if the lock fails, so every failed receive pins a psock forever. A tenant that loops interrupted receives on a kTLS+sockmap socket leaks kernel objects until the node runs out of memory.
Who can reach it
Local and unprivileged on the socket side - the reader lock fails on signal interruption or timeout, which the tenant controls. Requires the socket to also carry a BPF psock (sockmap), so it applies on nodes running a service mesh or CNI that combines sockmap with kTLS, not on plain kTLS sockets.
What to do
Boot a kernel carrying the linked stable commits. Interim: do not run sockmap/sk_msg policy over kTLS sockets, and cap per-tenant memory so a leak is bounded by the cgroup rather than the node.
References
Related entries
- Linux kernel (net/tls): KTLS stored a negative errno into the socket error field where a positive value is expected. ACVE-2021-47496 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCVE-2022-49094 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, soCVE-2024-26582 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completionCVE-2024-26583 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCVE-2024-26584 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async crypto callback signalled completion before scheduling the transmit work, so theCVE-2024-26585 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.