Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLS
Impact
When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLS encrypts and transmits the stale tail - uninitialized kernel memory is appended to a complete Application Data record and sent to the peer. Kernel heap bytes leave the node on the wire, and the receiver sees a malformed record.
Who can reach it
Requires an sk_msg/BPF policy calling bpf_msg_pop_data() attached to a kTLS TX socket - the shape of a service mesh or CNI sidecar doing L7 policy over encrypted traffic. The party who receives the leak is whoever is on the far end of the connection, which for a tenant-facing proxy can be the tenant itself. Attaching the policy needs CAP_BPF; reading the leaked bytes needs nothing.
What to do
Boot a kernel carrying the linked stable commits. Interim: stop running sk_msg programs that shorten payloads (bpf_msg_pop_data) over kTLS sockets, or terminate TLS in userspace on affected nodes.
References
Related entries
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileCVE-2021-47131 · Linux kernel (net/tls)High
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketCVE-2025-37756 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF verdict that grows the scatterlist (bpf_msg_push_data) combined with a cork_bytes settingCVE-2025-38166 · Linux kernel (net/tls)High
- Linux kernel (net/tls): KTLS assumes it owns the TCP receive queue. When another reader drains bytes first, the oldCVE-2025-38616 · Linux kernel (net/tls)High
- Linux kernel (net/tls): The kTLS device-offload setup resolved the socket's netdevice outside RCU, so the net_device itCVE-2025-40149 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.