Executive brief
A vulnerability exists in the Linux kernel's implementation of the Transport Layer Security (TLS) protocol. A local attacker could potentially cause a system crash or access sensitive information due to how the kernel handles data in the network receive queue. This issue occurs when non-standard data reading methods are used, leading to memory management errors.
Technical details
The Linux kernel TLS implementation (net/tls) incorrectly assumes exclusive ownership of the TCP socket receive queue. When using non-standard read APIs (e.g., zerocopy) or during specific race conditions where a reader enters before TLS ULP installation, data can be removed from the queue without the TLS layer's knowledge. This leads to an out-of-bounds read (CWE-125) because the TLS parser may attempt to access data based on a previously calculated record length that is no longer present in the socket. The vulnerability was characterized by a buggy early exit that left an anchor pointing to a freed socket buffer (skb). Patches replace the previous WARN_ON() with proper error handling that wipes the parsing state and triggers a retry.
Affected products
- Linux Linux Kernel 6.0 to 6.16.2
Timeline
- 2025-08-07: disclosed: Initial patch authored by Jakub Kicinski
- 2025-08-20: patched: Fixes merged into stable kernel branches
- 2025-08-22: advisory: CVE-2025-38616 published
References
- https://git.kernel.org/stable/c/2fb97ed9e2672b4f6e24ce206ac1a875ce4bcb38
- https://git.kernel.org/stable/c/6db015fc4b5d5f63a64a193f65d98da3a7fc811d
- https://git.kernel.org/stable/c/db3658a12d5ec4db7185ae7476151a50521b7207
- https://git.kernel.org/stable/c/eb0336f213fe88bbdb7d2b19c9c9ec19245a3155
- https://git.kernel.org/stable/c/f1fe99919f629f980d0b8a7ff16950bffe06a859