From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 656083A6B81 for ; Sun, 19 Jul 2026 15:42:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784475733; cv=none; b=sjL13vZKrKsbhXpSzfYL/x5SPjLJtDoc5jxXLUl3pm5Pb7RwBqAXwu5hARSpjnbyu37SK0137qHV7AuaclrPYPJ3xmu1QRckOXXqt4NyMU04e+4YhENK7OthBOyhEUQgQYee13KLKNC1EQBZdu+HW8gtV5c4HDu2wVpm9ELALgQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784475733; c=relaxed/simple; bh=qRU0hXcpfBo+MCp2Ukw0mJgxBaUW47oK111X9tRJoyA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Owk26sZTzx/Y8rP201bTkBpdHveO1oNV8tbuF8mS8tI4e60MouSechpOIbCKrU4p9sNUDoRo1GSrQNp7832u0JYRPsYaweKQgRFz9Kk/1sfsUZ2+SUsNNQRMNCLDE5OsPxpj64DqgmMpaWcvBgKnpqdXHqukBp2K1yYoJ0PnGk8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=LAVJDzdJ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="LAVJDzdJ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A04081F000E9; Sun, 19 Jul 2026 15:42:11 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784475732; bh=TLurhk1Q0Q81gdCDmSeS6cswYCRpaGruPCbB4Vk17FE=; h=From:To:Cc:Subject:Date:Reply-To; b=LAVJDzdJ6pHiy9UnlReZNZUtjbX8gSYzVe+mJWX+lk1JrYJ577jiy3cCQRhA/Z1ic IsYNOGRRLdzvF/ZA+6Sietyiq+EoMWbacuIoGKxMeMrDa5Qr7You99g9pZL9K8+FXf PTD6fOi9phj/zSLqV9s88ZDiYnnwXiiBxPNirXjg= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring Date: Sun, 19 Jul 2026 17:38:29 +0200 Message-ID: <2026071907-CVE-2026-64047-e420@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=4507; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Jgi9XDTnWt+UdpGbKKwrMncmSc42dtKdL3mi4hQRTq8=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkx7+Ntfbk41pua9m0R1jdPvMMmtbPY+1JC5R/FddUPq g1uvxPviGVhEGRikBVTZPmyjefo/opDil6Gtqdh5rAygQxh4OIUgInMU2NYsNfueXfX9lVH77zW OKD93KRfQ8p4PcOCpiqNy55+omtPBUaVeMy6EfothdkPAA== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg scatterlist ring wraps (sg.end < sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this: struct sk_msg_sg { [...] /* The extra two elements: * 1) used for chaining the front and sections when the list becomes * partitioned (e.g. end < start). The crypto APIs require the * chaining; * 2) to chain tailer SG entries after the message. */ struct scatterlist data[MAX_MSG_FRAGS + 2]; The current code uses MAX_SKB_FRAGS + 1 as the ring size: sg_chain(&msg_pl->sg.data[msg_pl->sg.start], MAX_SKB_FRAGS - msg_pl->sg.start + 1, msg_pl->sg.data); This places the chain pointer at sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. = &data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 = data[start + (MAX_SKB_FRAGS - start + 1) - 1] = data[MAX_SKB_FRAGS] instead of the true last entry. This is likely due to a "race" of the commit under Fixes landing close to commit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down") Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested by Sabrina). The Linux kernel CVE team has assigned CVE-2026-64047 to this issue. Affected and fixed versions =========================== Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 5.10.258 with commit 73963a375885d5ccb7def39fd0b4f542e0f343dd Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 5.15.209 with commit 47110c3a9ac247b688657337f5981efcfcb240dc Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.1.175 with commit 84158c2997159df4a0d70cd9c46774512d32a522 Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.6.142 with commit 131ef12057d92b77b636321b7849c69222405a97 Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.12.92 with commit 66339b71f105e6f83e0da3b9583d95077534fe1d Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 6.18.34 with commit eca989eab4b2599dcb02f72140a7c08f08838520 Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 7.0.11 with commit 2fb0dc7e0099686c4e9d2732745d8a31b18c3628 Issue introduced in 5.5 with commit 9aaaa56845a06aeabdd597cbe19492dc01f281ec and fixed in 7.1 with commit 285943c6e7ca309bbea84b253745154241d9788a Issue introduced in 5.4.14 with commit d529d6c9f7e3aaeac13c4948f79799ccb825f29d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-64047 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/tls/tls_sw.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522 https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97 https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520 https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628 https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a