Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): Tls_init published the new sk_prot before the TLS context was fully initialized, so a
Impact
Tls_init published the new sk_prot before the TLS context was fully initialized, so a concurrent setsockopt/getsockopt on the same socket can see ctx->sk_proto as NULL and dereference it. An unprivileged tenant gets a kernel NULL dereference out of the kTLS crypto-info setsockopt path.
Who can reach it
Local and unprivileged: one thread enables the TLS ULP while another calls setsockopt/getsockopt(SOL_TLS) on the same socket. No device node, no capability. The store-store reordering the race needs is real on weakly-ordered CPUs (arm64 - which is what Grace/GH200-class head nodes are), and much harder to hit on x86.
What to do
Boot a kernel carrying the linked stable commits. Interim: none at the tenant boundary; on arm64 nodes consider blacklisting the tls module where kTLS is not required.
References
Related entries
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): KTLS stored a negative errno into the socket error field where a positive value is expected. ACVE-2021-47496 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): KTLS allocates a 12-byte IV buffer for AES-128-CCM but the decrypt path copies 16 bytes out ofCVE-2022-49094 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The async decrypt completion released pages that the decrypt path never took a reference on, soCVE-2024-26582 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): The thread in recvmsg/sendmsg can exit as soon as the async crypto callback signals completionCVE-2024-26583 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the crypto queue is full the AEAD call returns -EBUSY instead of -EINPROGRESS and theCVE-2024-26584 · Linux kernel (net/tls)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.