Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): The kTLS device-offload setup resolved the socket's netdevice outside RCU, so the net_device it
Impact
The kTLS device-offload setup resolved the socket's netdevice outside RCU, so the net_device it hands to the NIC offload path can be freed underneath it - a use-after-free on the device object reached from a plain setsockopt call.
Who can reach it
Any unprivileged socket owner enabling kTLS NIC offload: setsockopt(SOL_TLS, TLS_TX/TLS_RX, ...) on a socket whose route or lower device is changing (bonding failover, link churn, veth teardown). This is the exact configuration used for offloaded storage and control-plane TLS on ConnectX-class NICs, so it is live on nodes that lean on kTLS offload.
What to do
Boot a kernel carrying the linked stable commits. Interim: disable kTLS device offload (ethtool -K <dev> tls-hw-tx-offload off / tls-hw-rx-offload off) so the software path is used, and avoid link churn on nodes with live kTLS offload sessions.
References
Related entries
- Linux kernel (net/tls): A receiver that holds its TCP window at zero keeps the kTLS sender blocked inside tx_lockCVE-2023-54306 · Linux kernel (net/tls)High
- Linux kernel (net/tls): If a page allocation fails while the TLS strparser is copying a partial record, the receiveCVE-2025-38018 · Linux kernel (net/tls)High
- Linux kernel (net/tls): The queue that pins encrypted input buffers while the AEAD engine still references them wasCVE-2026-23414 · Linux kernel (net/tls)High
- Linux kernel (net/tls): When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but neverCVE-2026-52974 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyCVE-2026-72330 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.