9.8

CVE-2026-64047

net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring

In the Linux kernel, the following vulnerability has been resolved:

net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring

When an sk_msg scatterlist ring wraps (sg.end < sg.start),
tls_push_record() chains the tail portion of the ring to the head
using sg_chain(). An extra entry in the sg array is reserved for
this:

  struct sk_msg_sg {
        [...]
        /* The extra two elements:
         * 1) used for chaining the front and sections when the list becomes
         *    partitioned (e.g. end < start). The crypto APIs require the
         *    chaining;
         * 2) to chain tailer SG entries after the message.
         */
        struct scatterlist              data[MAX_MSG_FRAGS + 2];

The current code uses MAX_SKB_FRAGS + 1 as the ring size:

    sg_chain(&msg_pl->sg.data[msg_pl->sg.start],
             MAX_SKB_FRAGS - msg_pl->sg.start + 1,
             msg_pl->sg.data);

This places the chain pointer at

  sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =
  &data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =
  data[start + (MAX_SKB_FRAGS - start + 1) - 1] =
  data[MAX_SKB_FRAGS]

instead of the true last entry. This is likely due to a "race" of
the commit under Fixes landing close to
commit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down")

Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested
by Sabrina).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 73963a375885d5ccb7def39fd0b4f542e0f343dd
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 47110c3a9ac247b688657337f5981efcfcb240dc
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 84158c2997159df4a0d70cd9c46774512d32a522
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 131ef12057d92b77b636321b7849c69222405a97
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 66339b71f105e6f83e0da3b9583d95077534fe1d
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < eca989eab4b2599dcb02f72140a7c08f08838520
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 2fb0dc7e0099686c4e9d2732745d8a31b18c3628
Status affected
Version 9aaaa56845a06aeabdd597cbe19492dc01f281ec
Version < 285943c6e7ca309bbea84b253745154241d9788a
Status affected
Version d529d6c9f7e3aaeac13c4948f79799ccb825f29d
Status affected
Version 5.4.14
Version < 5.5
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version 0
Version < 5.5
Status unaffected
Version <= 5.10.*
Version 5.10.258
Status unaffected
Version <= 5.15.*
Version 5.15.209
Status unaffected
Version <= 6.1.*
Version 6.1.175
Status unaffected
Version <= 6.6.*
Version 6.6.142
Status unaffected
Version <= 6.12.*
Version 6.12.92
Status unaffected
Version <= 6.18.*
Version 6.18.34
Status unaffected
Version <= 7.0.*
Version 7.0.11
Status unaffected
Version <= *
Version 7.1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.51% 0.407
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd
https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc
https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522
https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97
https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d
https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520
https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628
https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a