« Volver al listado

CVE-2026-80852

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tls: device: fix out-of-bounds write in tls_append_frag()

Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is otherwise only reachable on a machine with a NIC that implements the offload.

tls_push_data() only checks whether the open record still has room for another frag at the bottom of its loop, and the MSG_MORE early break skips that check.

Leer descripción completaMostrar menos

The record survives to the next syscall with the frag count it already had, and tls_append_frag() does not check either, so with TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds a non-coalescing pipe page and num_frags walks off the end of tls_record_info.frags[MAX_SKB_FRAGS]. Once the record is pushed, tls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and the sg_set_page() writes land on the destruct_work that follows it, which the workqueue then calls.

The byte limit is fine because copy drops to 0 and the loop falls through to the same check; the frag count has no such feedback.

Push the record rather than keep a full one open, which is what a plain TCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and new_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw already sets full_record when the sk_msg ring fills up, MSG_MORE or not.

and, once the record is pushed:

Detalles técnicos trazas, registros y código del informe original
  BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)
  Write of size 8 at addr ffff8881104d1530 by task tls_oob/450

  CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT
  Call Trace:
   <TASK>
   dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)
   print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)
   kasan_report (mm/kasan/report.c:595)
   tls_append_frag (net/tls/tls_device.c:269)
   tls_push_data (net/tls/tls_device.c:518)
   tls_device_sendmsg (net/tls/tls_device.c:583)
   inet_sendmsg (net/ipv4/af_inet.c:865)
   sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)
   splice_to_socket (fs/splice.c:884)
   do_splice (fs/splice.c:936 fs/splice.c:1349)
   __do_splice (fs/splice.c:1431)
   __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)
   do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)
   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)
   </TASK>

  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24
  index 18 is out of range for type 'skb_frag_t [17]'
  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41
  index 18 is out of range for type 'scatterlist [17]'
  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39
  index 18 is out of range for type 'scatterlist [17]'
  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38
  index 26 is out of range for type 'scatterlist [17]'

  kernel tried to execute NX-protected page - exploit attempt? (uid: 0)
  BUG: unable to handle page fault for address: ffffea000411a680
  #PF: supervisor instruction fetch in kernel mode
  #PF: error_code(0x0011) - permissions violation
  Oops: Oops: 0011 [#1] SMP KASAN PTI
  Workqueue: ktls_device_destruct 0xffffea000411a680
  RIP: 0010:0xffffea000411a680
  Call Trace:
   <TASK>
   worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)
   kthread (kernel/kthread.c:436)
   ret_from_fork (arch/x86/kernel/process.c:158)
   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
   </TASK>

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80852",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "03ced5da6120965d80ed56dbb7d78fa5c9128906",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "a832d7cb09da2a8e4e9734b4be14d3e76169d805",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "b7f10d4ff987bda038df90052cd4a1434a7412d4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "cd7e875b89597f3498917af764758391338d1802",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "7e1208c135618358da5d7d6664874dc6e53c62fc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e8f69799810c32dd40c6724d829eccc70baad07f",
              "lessThan": "b17cf742eaad70ae29ac558cefb3aa9bbeea03d4",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/tls/tls_device.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.18"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.18",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.187",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.156",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.108",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.49",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.13",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.3",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/tls/tls_device.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T16:18:14.073",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/03ced5da6120965d80ed56dbb7d78fa5c9128906",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e1208c135618358da5d7d6664874dc6e53c62fc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a832d7cb09da2a8e4e9734b4be14d3e76169d805",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b17cf742eaad70ae29ac558cefb3aa9bbeea03d4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/b7f10d4ff987bda038df90052cd4a1434a7412d4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cd7e875b89597f3498917af764758391338d1802",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/fadbc1ed2a872a8649a44cf9e1cf9621fc58cd6e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: device: fix out-of-bounds write in tls_append_frag()\n\nFound with syzkaller and a local syzbot instance running on top of a\nnetdevsim TLS offload emulation; tls_device.c is otherwise only reachable\non a machine with a NIC that implements the offload.\n\ntls_push_data() only checks whether the open record still has room for\nanother frag at the bottom of its loop, and the MSG_MORE early break\nskips that check.  The record survives to the next syscall with the frag\ncount it already had, and tls_append_frag() does not check either, so\nwith TLS_TX_ZEROCOPY_RO every splice(SPLICE_F_MORE) of a byte or two adds\na non-coalescing pipe page and num_frags walks off the end of\ntls_record_info.frags[MAX_SKB_FRAGS].  Once the record is pushed,\ntls_push_record() runs the same index over sg_tx_data[MAX_SKB_FRAGS] and\nthe sg_set_page() writes land on the destruct_work that follows it, which\nthe workqueue then calls.\n\nThe byte limit is fine because copy drops to 0 and the loop falls through\nto the same check; the frag count has no such feedback.\n\nPush the record rather than keep a full one open, which is what a plain\nTCP socket does - tcp_sendmsg_locked() uses tcp_mark_push() and\nnew_segment in both the copy and the MSG_SPLICE_PAGES paths, and tls_sw\nalready sets full_record when the sk_msg ring fills up, MSG_MORE or not.\n\n  BUG: KASAN: slab-out-of-bounds in tls_append_frag ( net/tls/tls_device.c:269)\n  Write of size 8 at addr ffff8881104d1530 by task tls_oob/450\n\n  CPU: 2 UID: 0 PID: 450 Comm: tls_oob Not tainted 7.2.0-rc7+ #329 PREEMPT\n  Call Trace:\n   <TASK>\n   dump_stack_lvl (lib/dump_stack.c:94 lib/dump_stack.c:120)\n   print_report (mm/kasan/report.c:378 mm/kasan/report.c:482)\n   kasan_report (mm/kasan/report.c:595)\n   tls_append_frag (net/tls/tls_device.c:269)\n   tls_push_data (net/tls/tls_device.c:518)\n   tls_device_sendmsg (net/tls/tls_device.c:583)\n   inet_sendmsg (net/ipv4/af_inet.c:865)\n   sock_sendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813)\n   splice_to_socket (fs/splice.c:884)\n   do_splice (fs/splice.c:936 fs/splice.c:1349)\n   __do_splice (fs/splice.c:1431)\n   __x64_sys_splice (fs/splice.c:1634 fs/splice.c:1616)\n   do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94)\n   entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121)\n   </TASK>\n\nand, once the record is pushed:\n\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:300:24\n  index 18 is out of range for type 'skb_frag_t [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:301:41\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:302:39\n  index 18 is out of range for type 'scatterlist [17]'\n  UBSAN: array-index-out-of-bounds in net/tls/tls_device.c:307:38\n  index 26 is out of range for type 'scatterlist [17]'\n\n  kernel tried to execute NX-protected page - exploit attempt? (uid: 0)\n  BUG: unable to handle page fault for address: ffffea000411a680\n  #PF: supervisor instruction fetch in kernel mode\n  #PF: error_code(0x0011) - permissions violation\n  Oops: Oops: 0011 [#1] SMP KASAN PTI\n  Workqueue: ktls_device_destruct 0xffffea000411a680\n  RIP: 0010:0xffffea000411a680\n  Call Trace:\n   <TASK>\n   worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)\n   kthread (kernel/kthread.c:436)\n   ret_from_fork (arch/x86/kernel/process.c:158)\n   ret_from_fork_asm (arch/x86/entry/entry_64.S:245)\n   </TASK>"
    }
  ],
  "lastModified": "2026-09-04T16:18:14.073",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}