Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLS
Impact
If the skb clone that pins the input buffer for an async decrypt cannot be allocated, kTLS proceeds with the decrypt anyway. The result is a use-after-free on the skb and, worse, the crypto engine writing plaintext into the caller's userspace buffer after recv() has already returned - so decrypted bytes land in whatever that address space has since reused the page.
Who can reach it
Remote and unauthenticated relative to the TLS data path: a peer sending records to any kTLS RX socket drives the async decrypt, and the failing clone allocation is inducible with memory pressure a co-tenant can generate. No device node or privilege needed; applies to tenant traffic and to node storage/control-plane connections using kTLS.
What to do
Boot a kernel carrying the linked stable commits. Interim: disable async crypto offload for kTLS (avoid cryptd-backed AEAD drivers) or terminate TLS in userspace on exposed nodes.
References
Related entries
- Linux kernel (net/tls): Closing a kTLS socket cancelled the transmit work item, but the write-space callback couldCVE-2026-23240 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the crypto engine backlogs a kTLS encrypt request, both the async completion callback andCVE-2026-31533 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCVE-2026-64046 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCVE-2026-64047 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.