๐Ÿ” CVE Alert

CVE-2026-64025

UNKNOWN 0.0

bpf, skmsg: fix verdict sk_data_ready racing with ktls rx

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and defers to psock->saved_data_ready when a TLS RX context is present, avoiding a conflict with the TLS strparser's ownership of the receive queue (commit e91de6afa81c, "bpf: Fix running sk_skb program types with ktls"). sk_psock_verdict_data_ready() has no equivalent guard. When a socket is inserted into a sockmap (BPF_SK_SKB_VERDICT) before TLS RX is configured, tls_sw_strparser_arm() saves sk_psock_verdict_data_ready as rx_ctx->saved_data_ready. On data arrival: tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready -> saved_data_ready() = sk_psock_verdict_data_ready() -> tcp_read_skb() drains sk_receive_queue via __skb_unlink() without calling tcp_eat_skb(), so copied_seq is not advanced. tls_strp_msg_load() then finds tcp_inq() >= full_len (stale), calls tcp_recv_skb() on the now-empty queue, hits WARN_ON_ONCE(!first), and returns with rx_ctx->strp.anchor.frag_list pointing at a psock-owned (potentially freed) skb. tls_decrypt_sg() subsequently walks that frag_list: use-after-free. Apply the same fix as sk_psock_strp_data_ready(): if a TLS RX context is present, call psock->saved_data_ready (sock_def_readable) to wake recv() waiters and return immediately, leaving the receive queue untouched. TLS retains sole ownership of the queue and decrypts the record normally through tls_sw_recvmsg().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ef5659280eb13e8ac31c296f58cfdfa1684ac06b < c9ea01768903ae47f210cd457af1dead6de7a9c3 ef5659280eb13e8ac31c296f58cfdfa1684ac06b < 7c8cf21bc4efb4af18d6096db3f8bd06d622251c ef5659280eb13e8ac31c296f58cfdfa1684ac06b < 1861d369efd62d67796563bf3e01fc22e5626f8b ef5659280eb13e8ac31c296f58cfdfa1684ac06b < 8a52139560f833c3975032e1f5762611e3a36d71 ef5659280eb13e8ac31c296f58cfdfa1684ac06b < ddf8029623a1af20e984c040e89ff918158397ab
Linux / Linux
5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3 git.kernel.org: https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c git.kernel.org: https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b git.kernel.org: https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71 git.kernel.org: https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab