From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 35CFA381B1D for ; Fri, 4 Sep 2026 15:57:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537463; cv=none; b=agBhfot/7oYZ0uSdV9ijFq6IlBM85qSi8kWL117i/g7J6vJ2Rp/4jCNvzytBQGEjYXrdjrmuErtCvhDEh35bmEZ4UsiwnwwE2JHlqdPP9ULvHOWjRtyeZr0w7yyobE2/cnboxdihrLMfFOL2fSC4Y0gUU7NceMtrQTt4NBwgO/M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788537463; c=relaxed/simple; bh=nmkagnuhSqsGYpI2j9vLcel2BRV6hr6HipiTYNN6dgU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=GI/1S80kplyviJlzRK22WlS0nO8nA2YjZ7thFVrgh0ZFYRw2WmH1XR0mjnuPUWLeBVW3K2TTPftqcwn5s2O5BWU0ZO4NBZOQPlHhp1SjBNSWNGvhDXT67FisfNKr5T58Oo9EPgViyyI+6s78efKR57wJafPQUzYrI2OYOLa8uzE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=2B2IProQ; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="2B2IProQ" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 111371F00A3D; Fri, 4 Sep 2026 15:57:40 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1788537461; bh=xLrhHVO7oh9rj+gCeEB5RBS1OJA/ucrZowdkLxNYokQ=; h=From:To:Cc:Subject:Date:Reply-To; b=2B2IProQtiecsgK0lb237l/kPF6N4ZkhzeFvCvQp5aScCbiDmx9sCwYeLP9g9mBVx mgO+b4S9bWDvFgHmss/hPYvtwV9ygpGX1F7XYGOHxwc6FslXnHCWl4J0fVVWaxLFOM gKBPpDNM9MF1gqqTy5S44F7WQxGB2W3cjimzSpDE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-80852: tls: device: fix out-of-bounds write in tls_append_frag() Date: Fri, 4 Sep 2026 17:53:19 +0200 Message-ID: <2026090400-CVE-2026-80852-1072@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=6350; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=3i/8IyjxZY44a7cXPme4XVpsP6FA5NQyWvFaAMVfV98=; b=owGbwMvMwCRo6H6F97bub03G02pJDFmzXsZYM6k+/eoy+cI0e7vaT8vaklzqywq/Tu0zz7UPn Gfju8WlI5aFQZCJQVZMkeXLNp6j+ysOKXoZ2p6GmcPKBDKEgYtTACbizMGw4NLJnVqSK0vtHVgl G7/MlW2bcCiulWHB9SVLAlkb7uyOePRVrt9o5fkHCQt5AQ== X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: tls: device: fix out-of-bounds write in tls_append_frag() Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is otherwise only reachable on a machine with a NIC that implements the offload. tls_push_data() only checks whether the open record still has room for another frag at the bottom of its loop, and the MSG_MORE early break skips that check. The record survives to the next syscall with the frag count it already had, and tls_append_frag() does not check either, so with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds a non-coalescing pipe page and num_frags walks off the end of tls_record_info.frags[MAX_SKB_FRAGS]. Once the record is pushed, tls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and the sg_set_page() writes land on the destruct_work that follows it, which the workqueue then calls. The byte limit is fine because copy drops to 0 and the loop falls through to the same check; the frag count has no such feedback. Push the record rather than keep a full one open, which is what a plain TCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and new_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw already sets full_record when the sk_msg ring fills up, MSG_MORE or not. BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269) Write of size 8 at addr ffff8881104d1530 by task tls_oob/450 CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT Call Trace: dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120) print_report (mm/kasan/report.c:378 mm/kasan/report.c:482) kasan_report (mm/kasan/report.c:595) tls_append_frag (net/tls/tls_device.c:269) tls_push_data (net/tls/tls_device.c:518) tls_device_sendmsg (net/tls/tls_device.c:583) inet_sendmsg (net/ipv4/af_inet.c:865) sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813) splice_to_socket (fs/splice.c:884) do_splice (fs/splice.c:936 fs/splice.c:1349) __do_splice (fs/splice.c:1431) __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616) do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) and, once the record is pushed: UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24 index 18 is out of range for type 'skb_frag_t [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38 index 26 is out of range for type 'scatterlist [17]' kernel tried to execute NX-protected page - exploit attempt? (uid: 0) BUG: unable to handle page fault for address: ffffea000411a680 #PF: supervisor instruction fetch in kernel mode #PF: error_code(0x0011) - permissions violation Oops: Oops: 0011 [#1] SMP KASAN PTI Workqueue: ktls_device_destruct 0xffffea000411a680 RIP: 0010:0xffffea000411a680 Call Trace: worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) ret_from_fork (arch/x86/kernel/process.c:158) ret_from_fork_asm (arch/x86/entry/entry_64.S:245) The Linux kernel CVE team has assigned CVE-2026-80852 to this issue. Affected and fixed versions =========================== Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.1.187 with commit 03ced5da6120965d80ed56dbb7d78fa5c9128906 Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.6.156 with commit a832d7cb09da2a8e4e9734b4be14d3e76169d805 Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.12.108 with commit b7f10d4ff987bda038df90052cd4a1434a7412d4 Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 6.18.49 with commit fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.1.13 with commit cd7e875b89597f3498917af764758391338d1802 Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.2.3 with commit 7e1208c135618358da5d7d6664874dc6e53c62fc Issue introduced in 4.18 with commit e8f69799810c32dd40c6724d829eccc70baad07f and fixed in 7.3-rc1 with commit b17cf742eaad70ae29ac558cefb3aa9bbeea03d4 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-80852 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: net/tls/tls_device.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906 https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805 https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4 https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802 https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4