* CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
@ 2026-07-19 15:38 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-07-19 15:38 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
When an sk_msg scatterlist ring wraps (sg.end < sg.start),
tls_push_record() chains the tail portion of the ring to the head
using sg_chain(). An extra entry in the sg array is reserved for
this:
struct sk_msg_sg {
[...]
/* The extra two elements:
* 1) used for chaining the front and sections when the list becomes
* partitioned (e.g. end < start). The crypto APIs require the
* chaining;
* 2) to chain tailer SG entries after the message.
*/
struct scatterlist data[MAX_MSG_FRAGS + 2];
The current code uses MAX_SKB_FRAGS + 1 as the ring size:
sg_chain(&msg_pl->sg.data[msg_pl->sg.start],
MAX_SKB_FRAGS - msg_pl->sg.start + 1,
msg_pl->sg.data);
This places the chain pointer at
sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =
&data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =
data[start + (MAX_SKB_FRAGS - start + 1) - 1] =
data[MAX_SKB_FRAGS]
instead of the true last entry. This is likely due to a "race" of
the commit under Fixes landing close to
commit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down")
Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested
by Sabrina).
The Linux kernel CVE team has assigned CVE-2026-64047 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 5.10.258 with commit 73963a375885d5ccb7def39fd0b4f542e0f343dd
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 5.15.209 with commit 47110c3a9ac247b688657337f5981efcfcb240dc
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.1.175 with commit 84158c2997159df4a0d70cd9c46774512d32a522
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.6.142 with commit 131ef12057d92b77b636321b7849c69222405a97
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.12.92 with commit 66339b71f105e6f83e0da3b9583d95077534fe1d
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.18.34 with commit eca989eab4b2599dcb02f72140a7c08f08838520
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 7.0.11 with commit 2fb0dc7e0099686c4e9d2732745d8a31b18c3628
Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 7.1 with commit 285943c6e7ca309bbea84b253745154241d9788a
Issue introduced in 5.4.14 with commit d529d6c9f7e3aaeac13c4948f79799ccb825f29d
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-64047
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/tls/tls_sw.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd
https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc
https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522
https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97
https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d
https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520
https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628
https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-07-19 15:42 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-19 15:38 CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.