Executive brief
A vulnerability exists in the Linux kernel's Transport Layer Security (TLS) implementation. The TLS component is responsible for encrypting data sent over a network to ensure privacy and security. An exploit could allow an attacker to cause a system crash or potentially execute unauthorized actions by triggering a race condition that accesses memory after it has been freed, impacting the reliability and security of the server.
Technical details
A race condition exists in the Linux kernel TLS implementation within the tls_sw_cancel_work_tx() function. When a TLS socket is closed via tls_sk_proto_close(), the tx_work_handler() can still be rescheduled by other kernel paths like the Delayed ACK handler or ksoftirqd after cancel_delayed_work_sync() has been called. This results in a use-after-free scenario where the worker thread dereferences a TLS object that has already been freed. The vulnerability is addressed by replacing cancel_delayed_work_sync() with disable_delayed_work_sync() to ensure the work cannot be rescheduled during the closing process. This issue was identified as CWE-362.
Affected products
- Linux Linux Kernel versions from 5.3.1 up to 6.12.75, 6.13 up to 6.18.16, 6.19 up to 6.19.6
Timeline
- 2026-03-10: advisory: Initial disclosure and NVD publication
- 2026-02-23: patched: Fix committed to the Linux kernel tree