Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receive
Impact
If a page allocation fails while the TLS strparser is copying a partial record, the receive queue's frag_list is left NULL while full_len still says a record is in flight. The next data_ready dereferences NULL inside the TCP receive softirq - a kernel panic in interrupt context, taking the whole node and every tenant on it.
Who can reach it
Any kTLS RX socket on the node plus memory pressure. A co-tenant can create the pressure (that is a normal condition on a packed GPU node), and the peer keeps feeding partial records; the crash lands in tcp_data_queue -> tls_data_ready -> tls_strp_check_rcv, not in a task context that can be killed cleanly.
What to do
Boot a kernel carrying the linked stable commits. Interim: keep hard memory limits and reserves on tenant cgroups so the node does not enter page-allocation failure while kTLS connections are live.
References
Related entries
- Linux kernel (net/tls): The queue that pins encrypted input buffers while the AEAD engine still references them wasCVE-2026-23414 · Linux kernel (net/tls)High
- Linux kernel (net/tls): When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but neverCVE-2026-52974 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyCVE-2026-72330 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives theCVE-2023-52767 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistCVE-2024-35841 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.