* CVE-2026-80852: tls: device: fix out-of-bounds write in tls_append_frag()
@ 2026-09-04 15:53 Greg Kroah-Hartman
0 siblings, 0 replies; only message in thread
From: Greg Kroah-Hartman @ 2026-09-04 15:53 UTC (permalink / raw)
To: linux-cve-announce; +Cc: Greg Kroah-Hartman
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
tls: device: fix out-of-bounds write in tls_append_frag()
Found with syzkaller and a local syzbot instance running on top of a
netdevsim TLS offload emulation; tls_device.c is otherwise only reachable
on a machine with a NIC that implements the offload.
tls_push_data() only checks whether the open record still has room for
another frag at the bottom of its loop, and the MSG_MORE early break
skips that check. The record survives to the next syscall with the frag
count it already had, and tls_append_frag() does not check either, so
with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds
a non-coalescing pipe page and num_frags walks off the end of
tls_record_info.frags[MAX_SKB_FRAGS]. Once the record is pushed,
tls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and
the sg_set_page() writes land on the destruct_work that follows it, which
the workqueue then calls.
The byte limit is fine because copy drops to 0 and the loop falls through
to the same check; the frag count has no such feedback.
Push the record rather than keep a full one open, which is what a plain
TCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and
new_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw
already sets full_record when the sk_msg ring fills up, MSG_MORE or not.
BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)
Write of size 8 at addr ffff8881104d1530 by task tls_oob/450
CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT
Call Trace:
<TASK>
dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
kasan_report (mm/kasan/report.c:595)
tls_append_frag (net/tls/tls_device.c:269)
tls_push_data (net/tls/tls_device.c:518)
tls_device_sendmsg (net/tls/tls_device.c:583)
inet_sendmsg (net/ipv4/af_inet.c:865)
sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)
splice_to_socket (fs/splice.c:884)
do_splice (fs/splice.c:936 fs/splice.c:1349)
__do_splice (fs/splice.c:1431)
__x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)
do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
</TASK>
and, once the record is pushed:
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24
index 18 is out of range for type 'skb_frag_t [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41
index 18 is out of range for type 'scatterlist [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39
index 18 is out of range for type 'scatterlist [17]'
UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38
index 26 is out of range for type 'scatterlist [17]'
kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
BUG: unable to handle page fault for address: ffffea000411a680
#PF: supervisor instruction fetch in kernel mode
#PF: error_code(0x0011) - permissions violation
Oops: Oops: 0011 [#1] SMP KASAN PTI
Workqueue: ktls_device_destruct 0xffffea000411a680
RIP: 0010:0xffffea000411a680
Call Trace:
<TASK>
worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
</TASK>
The Linux kernel CVE team has assigned CVE-2026-80852 to this issue.
Affected and fixed versions
===========================
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.1.187 with commit 03ced5da6120965d80ed56dbb7d78fa5c9128906
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.6.156 with commit a832d7cb09da2a8e4e9734b4be14d3e76169d805
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.12.108 with commit b7f10d4ff987bda038df90052cd4a1434a7412d4
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.18.49 with commit fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.1.13 with commit cd7e875b89597f3498917af764758391338d1802
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.2.3 with commit 7e1208c135618358da5d7d6664874dc6e53c62fc
Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.3-rc1 with commit b17cf742eaad70ae29ac558cefb3aa9bbeea03d4
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-80852
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
net/tls/tls_device.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906
https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805
https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4
https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e
https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802
https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc
https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-04 15:57 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-04 15:53 CVE-2026-80852: tls: device: fix out-of-bounds write in tls_append_frag() Greg Kroah-Hartman
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.