Executive brief
A vulnerability in the Linux kernel's TLS implementation could lead to data corruption or the transmission of uninitialized memory. When the system processes encrypted network traffic using specific socket policies, it may fail to correctly calculate the size of the encrypted data, resulting in extra, meaningless bytes being appended to secure messages. This can cause communication errors or potentially expose sensitive information from the system's memory to the network recipient.
Technical details
The vulnerability is classified as a 'Use of Uninitialized Resource' (CWE-908) within the net/tls/tls_sw.c component of the Linux kernel. When sending plaintext data via kTLS, the kernel initially calculates the ciphertext length; however, if a BPF program subsequently uses bpf_msg_pop_data() to reduce the plaintext length, the corresponding ciphertext length is not updated. This results in the transmission of buffers containing uninitialized data appended to the TLS 'Application Data' packet. An attacker could potentially leverage this to leak sensitive kernel memory or cause denial-of-service due to TLS record parsing errors on the receiving end. The issue has been resolved by adding a call to sk_msg_trim to synchronize the encrypted message size when a delta is detected after BPF verdict execution.
Affected products
- Linux Linux Kernel 5.0 to 6.13, 5.4.297, 5.10.241, 5.15.190
Timeline
- 2025-06-09: patched: Initial patch authored
- 2025-08-19: disclosed: CVE published
References
- https://git.kernel.org/stable/c/0e853c1464bcf61207f8b5c32d2ac5ee495e859d
- https://git.kernel.org/stable/c/16aca8bb4ad0d8a13c8b6da4007f4e52d53035bb
- https://git.kernel.org/stable/c/178f6a5c8cb3b6be1602de0964cd440243f493c9
- https://git.kernel.org/stable/c/1e480387d4b42776f8957fb148af9d75ce93b96d
- https://git.kernel.org/stable/c/6ba20ff3cdb96a908b9dc93cf247d0b087672e7c
- https://git.kernel.org/stable/c/73fc5d04009d3969ff8e8574f0fd769f04124e59
- https://git.kernel.org/stable/c/849d24dc5aed45ebeb3490df429356739256ac40