Junglewise Threat Intelligence

CVE-2025-38616: Linux Kernel out-of-bounds read in TLS ULP receive queue

CVE-2025-38616 · Severity: high · CVSS 7.8 · Published 2025-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's implementation of the Transport Layer Security (TLS) protocol. A local attacker could potentially cause a system crash or access sensitive information due to how the kernel handles data in the network receive queue. This issue occurs when non-standard data reading methods are used, leading to memory management errors.

Technical details

The Linux kernel TLS implementation (net/tls) incorrectly assumes exclusive ownership of the TCP socket receive queue. When using non-standard read APIs (e.g., zerocopy) or during specific race conditions where a reader enters before TLS ULP installation, data can be removed from the queue without the TLS layer's knowledge. This leads to an out-of-bounds read (CWE-125) because the TLS parser may attempt to access data based on a previously calculated record length that is no longer present in the socket. The vulnerability was characterized by a buggy early exit that left an anchor pointing to a freed socket buffer (skb). Patches replace the previous WARN_ON() with proper error handling that wipes the parsing state and triggers a retry.

Affected products

  • Linux Linux Kernel 6.0 to 6.16.2

Timeline

  • 2025-08-07: disclosed: Initial patch authored by Jakub Kicinski
  • 2025-08-20: patched: Fixes merged into stable kernel branches
  • 2025-08-22: advisory: CVE-2025-38616 published

References

Related threats