Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but never
Impact
When kTLS RX offload fails at tls_dev_add, the rollback frees the software context but never frees the strparser anchor skb allocated during init. Every failed offload attempt leaks an skb, so a tenant that loops failing setsockopt calls bleeds kernel memory until the node starts OOM-killing other tenants' workloads.
Who can reach it
Local and unprivileged, no device node: setsockopt(SOL_TLS, TLS_RX) on a socket bound to a NIC that advertises kTLS RX offload but rejects the add - which happens once the NIC's offload contexts are exhausted, a state the same tenant can create. Only affects nodes with kTLS RX offload-capable NICs (ConnectX-class), which is exactly the storage-path configuration in these fleets.
What to do
Boot a kernel carrying the linked stable commits. Interim: disable kTLS RX hardware offload (ethtool -K <dev> tls-hw-rx-offload off) so the failing add path is never taken, and cap per-tenant memory.
References
Related entries
- Linux kernel (net/tls): A remote peer sends a zero-length TLS 1.3 application_data record - which the RFC explicitlyCVE-2026-72330 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF sockmap psock could be attached to a socket that already had the kTLS ULP installed. TheCVE-2022-49732 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Sendfile() on a kTLS socket whose plaintext and ciphertext buffers are both empty drives theCVE-2023-52767 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Splice with MSG_SPLICE_PAGES and MSG_MORE could push more pages into the plaintext scatterlistCVE-2024-35841 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Tls_init published the new sk_prot before the TLS context was fully initialized, so aCVE-2024-36489 · Linux kernel (net/tls)Medium
- Linux kernel (net/tls): Tls_sw_recvmsg takes a psock reference before acquiring the reader lock and returns withoutCVE-2024-35908 · Linux kernel (net/tls)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.