Junglewise Threat Intelligence

CVE-2026-64047: Linux kernel off-by-one in net/tls sg_chain entry count

CVE-2026-64047 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Transport Layer Security (TLS) implementation. The issue occurs when processing specific network message structures, potentially leading to memory management errors. An attacker could exploit this to cause system instability or potentially gain unauthorized access to kernel memory.

Technical details

An off-by-one error exists in the net/tls component of the Linux kernel during the handling of wrapped sk_msg scatterlist rings. When a ring wraps (sg.end < sg.start), the tls_push_record() function incorrectly calculates the entry count for sg_chain(), placing the chain pointer at an incorrect index (MAX_SKB_FRAGS) instead of the intended last entry. This logic error stems from using an incorrect ring size constant during chaining. The vulnerability could lead to memory corruption or out-of-bounds access within the kernel's networking stack. Patches have been released across multiple stable kernel branches to use ARRAY_SIZE for correct bounds calculation.

Affected products

  • Linux Linux kernel 9aaaa56845a0 to 73963a375885 (git)
  • Linux Linux kernel 9aaaa56845a0 to 47110c3a9ac2 (git)
  • Linux Linux kernel 9aaaa56845a0 to 84158c299715 (git)
  • Linux Linux kernel 9aaaa56845a0 to 131ef12057d9 (git)
  • Linux Linux kernel 9aaaa56845a0 to 66339b71f105 (git)
  • Linux Linux kernel 9aaaa56845a0 to eca989eab4b2 (git)

Timeline

  • 2026-05-11: disclosed: Initial patch submitted by Jakub Kicinski
  • 2026-06-01: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2026-07-19: advisory: CVE published in NVD dataset

References

Related threats