Executive brief
A vulnerability was identified in the Linux kernel's TLS (Transport Layer Security) implementation that could lead to system instability or crashes. The issue occurs when the system incorrectly handles data structures used for encryption, creating an invalid sequence that the system's cryptographic components cannot process. This affects how the kernel manages secure network traffic, potentially impacting the reliability of encrypted communications.
Technical details
The vulnerability exists in net/tls/tls_sw.c within the Linux kernel's TLS implementation. When processing plain text scatterlists (SG), specifically when the 'end' index is 0 but 'start' is non-zero, the code incorrectly creates a wrap link followed immediately by another chain link to the content type. Because the scatterlist API's sg_next iterator does not recursively resolve consecutive chain links, this results in an 'illegal input' to the crypto subsystem. This issue primarily affects TLS 1.3 implementations using BPF sockmaps. The fix involves skipping unnecessary wrapping when end=0 and reordering the chaining logic to ensure valid SGL structures.
Affected products
- Linux Linux Kernel 9aaaa56845a0 to 49a5faaa471ddcd37b6893970c9916eb836e7c31
Timeline
- 2026-05-11: disclosed: Initial patch authored by Jakub Kicinski
- 2026-06-01: patched: Patch committed to stable trees
- 2026-07-19: advisory: CVE published to NVD dataset
References
- https://git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d
- https://git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31
- https://git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3
- https://git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a
- https://git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235
- https://git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d
- https://git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36