Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When the crypto engine backlogs a kTLS encrypt request, both the async completion callback and
Impact
When the crypto engine backlogs a kTLS encrypt request, both the async completion callback and the synchronous error path clean up the same record. The double decrement corrupts the pending-operation sentinel, so the socket stops waiting for outstanding async encryptions entirely - a later send then frees the TLS record while the crypto callback is still holding it, and the callback fires on freed memory. Kernel heap use-after-free reachable by any process using kTLS, which on these nodes is the storage and control plane.
Who can reach it
Any local process that owns a socket and calls setsockopt(TLS_TX) - no privilege beyond owning the socket, so every tenant container has it - can drive this by pushing enough data to backlog the crypto engine. Loading the fleet's crypto queue is easy for a co-tenant, and the CNA scores it network-reachable because a peer that drives sustained TLS traffic contributes to the same backlog condition. No device node and no CAP_NET_ADMIN required.
What to do
Update to 5.15.203 / 6.1.169 / 6.6.135 / 6.8 or later. Interim control: there is no clean one - kTLS is attachable by any socket owner. If a fleet cannot be rebooted promptly, disabling the kTLS ULP (blacklist tls) removes the reachable path at the cost of falling back to userspace TLS.
References
Related entries
- Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at anotherCVE-2026-64046 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCVE-2026-64047 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileCVE-2021-47131 · Linux kernel (net/tls)High
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketCVE-2025-37756 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.