Junglewise Threat Intelligence

CVE-2026-23240: Linux Kernel race condition in tls_sw_cancel_work_tx

CVE-2026-23240 · Severity: critical · CVSS 9.8 · Published 2026-03-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Transport Layer Security (TLS) implementation. The TLS component is responsible for encrypting data sent over a network to ensure privacy and security. An exploit could allow an attacker to cause a system crash or potentially execute unauthorized actions by triggering a race condition that accesses memory after it has been freed, impacting the reliability and security of the server.

Technical details

A race condition exists in the Linux kernel TLS implementation within the tls_sw_cancel_work_tx() function. When a TLS socket is closed via tls_sk_proto_close(), the tx_work_handler() can still be rescheduled by other kernel paths like the Delayed ACK handler or ksoftirqd after cancel_delayed_work_sync() has been called. This results in a use-after-free scenario where the worker thread dereferences a TLS object that has already been freed. The vulnerability is addressed by replacing cancel_delayed_work_sync() with disable_delayed_work_sync() to ensure the work cannot be rescheduled during the closing process. This issue was identified as CWE-362.

Affected products

  • Linux Linux Kernel versions from 5.3.1 up to 6.12.75, 6.13 up to 6.18.16, 6.19 up to 6.19.6

Timeline

  • 2026-03-10: advisory: Initial disclosure and NVD publication
  • 2026-02-23: patched: Fix committed to the Linux kernel tree

References

Related threats