« Volver al listado

CVE-2026-80904

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Fail tls_sw_splice_read() after a failed async decrypt

When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record that did not authenticate breaks the connection.

tls_sw_splice_read() has no such check, and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenever a record is already parsed, and the first reader to reach sock_error() clears it, while async_wait.err persists.

Leer descripción completaMostrar menos

A splice therefore keeps delivering records on a connection that recvmsg() and read_sock() refuse to read.

Read async_wait.err in tls_sw_splice_read() as the other two readers do.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80904",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "a808aadff634c7a408b2ab84d5919e9a741fdb5b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "06c2a53604fa1dc4820063828d7dadb3675b7af8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "18ae1e95f20867106a28820c208a9cec99dda861",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "82d9269f01ebfd835b6256aa17016a974cbbc647",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "4b177911eb9f799e9841c2f87c75b08cb112757a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f314bfee81b1bf8e01168177b2f65f24eb8da63a",
              "lessThan": "976df67f463db1fddaf2a32fb04f57ad2891a23d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/tls/tls_sw.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.19"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.19",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.184",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.153",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.105",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.46",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/tls/tls_sw.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-04T18:17:59.983",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/tls: Fail tls_sw_splice_read() after a failed async decrypt\n\nWhen an async decrypt fails, tls_decrypt_done() records the error in\nctx->async_wait.err and calls tls_err_abort(), which stores it in\nsk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read\nasync_wait.err once they hold the reader lock and fail the call: a\nrecord that did not authenticate breaks the connection.\n\ntls_sw_splice_read() has no such check, and sk_err does not stand in\nfor one. tls_rx_rec_wait() tests sk_err only inside the loop it\nskips whenever a record is already parsed, and the first reader to\nreach sock_error() clears it, while async_wait.err persists. A\nsplice therefore keeps delivering records on a connection that\nrecvmsg() and read_sock() refuse to read.\n\nRead async_wait.err in tls_sw_splice_read() as the other two readers\ndo."
    }
  ],
  "lastModified": "2026-09-04T18:17:59.983",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}