Junglewise Threat Intelligence

CVE-2026-74610: Linux kernel TLS memory corruption in sk_msg ring handling

CVE-2026-74610 · Severity: high · CVSS 7.8 · Published 2026-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's TLS implementation contains a flaw in how it manages plaintext message buffers (sk_msg rings) during network transmission. When a buffer fills completely, the kernel fails to properly mark and flush the data, allowing subsequent operations to overwrite live data in memory. An unprivileged local user can exploit this to cause a kernel crash or potentially achieve privilege escalation through memory corruption.

Technical details

The vulnerability exists in tls_sw_sendmsg_locked() in net/tls/tls_sw.c, where the copy path fails to set the full_record flag when the plaintext sk_msg ring becomes full. This leaves an unpushed full ring that subsequent splice() operations can write to; since sk_msg_page_add() lacks its own fullness check, the scattergather list pointers (sg.end and sg.start) wrap around, making the ring appear empty. Fragments added afterward overwrite live data, and when the record is eventually pushed, the scatterwalk runs off the end of the list, causing a kernel NULL pointer dereference. An unprivileged user can trigger this locally by attaching the TLS ULP (Upper Layer Protocol) to a loopback TCP socket and performing specific send/splice operations. The fix adds fullness checks and proper record trimming to prevent this corruption.

Affected products

  • Linux Linux kernel 5.14 and later (vulnerable since MSG_SPLICE_PAGES support added in commit fe1e81d4f73b)

Timeline

  • 2026-08-22: disclosed
  • 2026-08-19: patched: Fix committed to stable kernel tree

References

Related threats