Database/Kernel, userspace & hypervisor
Linux kernel (net/tls): A particular kTLS ring state builds a scatterlist whose chain link points directly at another
Impact
A particular kTLS ring state builds a scatterlist whose chain link points directly at another chain link. The scatterlist iterator does not resolve chained links recursively, so this is illegal input to the crypto API - the AEAD walk runs off into whatever the second link descriptor happens to be. The practical outcome is the crypto engine reading and writing memory outside the record's buffers during TLS encryption, on the same code path that carries storage and control traffic.
Who can reach it
Any unprivileged local process that enables kTLS on its socket with setsockopt(TLS_TX) and drives the send ring into the wrapped state (ring end at zero with a non-zero start). Every tenant container can do this - kTLS attachment needs no capability. TLS 1.3 records make the condition easier to hit because they consume the reserved wrap slot for content-type chaining.
What to do
Boot a kernel carrying the fix commits below - the record's version field (5.5) is the introducing release, not a fix. Interim control: blacklist the tls ULP module so tenants cannot attach kTLS, at the cost of userspace TLS performance.
References
Related entries
- Linux kernel (net/tls): When the kTLS transmit scatterlist ring wraps, the chain link that stitches the tail back toCVE-2026-64047 · Linux kernel (net/tls)Critical
- Linux kernel (net/tls): When a BPF socket policy shrinks the plaintext after the ciphertext length was computed, kTLSCVE-2025-38608 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A non-DATA record already copied out of the pending list could be merged with a second recordCVE-2024-58239 · Linux kernel (net/tls)High
- Linux kernel (net/tls): When a NIC with active kTLS offload goes down, the offload teardown freed the TLS context whileCVE-2021-47131 · Linux kernel (net/tls)High
- Linux kernel (net/tls): KTLS never supported disconnect, but nothing stopped it. A connect(AF_UNSPEC) on a TLS socketCVE-2025-37756 · Linux kernel (net/tls)High
- Linux kernel (net/tls): A BPF verdict that grows the scatterlist (bpf_msg_push_data) combined with a cork_bytes settingCVE-2025-38166 · Linux kernel (net/tls)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.