Executive brief
A vulnerability has been identified in the Linux kernel's Transport Layer Security (TLS) implementation. The issue occurs when the system attempts to identify the network hardware associated with a secure connection, potentially leading to a system crash or unauthorized memory access. This could allow a local user to disrupt system operations or potentially gain elevated privileges on the affected device.
Technical details
A use-after-free (UAF) vulnerability exists in net/tls/tls_device.c within the Linux kernel. The function get_netdev_for_sock() is invoked during setsockopt() operations without proper RCU (Read-Copy-Update) protection. By accessing sk_dst_get(sk)->dev outside of an RCU critical section, the kernel may reference a network device object that has already been freed. An attacker with local access can exploit this race condition to trigger a kernel panic (DoS) or potentially execute arbitrary code in kernel mode. The fix involves implementing proper RCU locking and using __sk_dst_get() and dst_dev_rcu() to safely retrieve the network device reference.
Affected products
- Linux Linux 4.18 to 6.11.y
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6
Timeline
- 2025-09-16: disclosed: Initial patch submitted by Kuniyuki Iwashima
- 2025-11-12: advisory: CVE published
References
- https://git.kernel.org/stable/c/13159c7125636371543a82cb7bbae00ab36730cc
- https://git.kernel.org/stable/c/2b1bef126bbb8d0da51491357559126d567c1dee
- https://git.kernel.org/stable/c/c65f27b9c3be2269918e1cbad6d8884741f835c5
- https://git.kernel.org/stable/c/e37ca0092ddace60833790b4ad7a390408fb1be9
- https://git.kernel.org/stable/c/f09cd209359a23f88d4f3fa3d2379d057027e53c
- https://git.kernel.org/stable/c/feb474ddbf26b51f462ae2e60a12013bdcfc5407
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html