« Volver al listado

CVE-2026-93824

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

tls: reject the combination of TLS and sockmap

TLS and sockmap (BPF psock) integration hides a lot of latent bugs. Bugs which may be more or less relevant for real users but they are definitely exploitable.

We could not find anyone actively using this integration so let's reject this config. Adding a TLS socket to a sockmap was already rejected by sk_psock_init() through the inet_csk_has_ulp() check. We need to reject the attempts to configure the TLS keys (rather than adding the ULP itself) because checking prior to the ULP installation is tricky without risking a race with sockmap getting added in parallel (sockmap does not hold the socket lock).

Leer descripción completaMostrar menos

This patch is a minimal rejection of the feature. Subsequent patch in the series will do a light dead code removal. Full cleanup would require a major rewrite of the Tx path, we don't need skmsg any more.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-93824",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
              "lessThan": "c4896592744f30ff026f799947c5978bcfd7c8c7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
              "lessThan": "e26aa709454d48c3b3ef8d3100c8a04e7d9fd94e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
              "lessThan": "c3d4d537337f69e405a36fa561e7292ee4148bf7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
              "lessThan": "a08e780b6cc1153cbff8be55de9ec9da809e344f",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "d3b18ad31f93d0b6bae105c679018a1ba7daa9ca",
              "lessThan": "460e6486617c17dd19abe8f3fc67d9a6fa25f8ca",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "net/tls/tls_main.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.20",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.189",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.158",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.111",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.53",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/tls/tls_main.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-24T17:17:16.073",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/460e6486617c17dd19abe8f3fc67d9a6fa25f8ca",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a08e780b6cc1153cbff8be55de9ec9da809e344f",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c3d4d537337f69e405a36fa561e7292ee4148bf7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c4896592744f30ff026f799947c5978bcfd7c8c7",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e26aa709454d48c3b3ef8d3100c8a04e7d9fd94e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntls: reject the combination of TLS and sockmap\n\nTLS and sockmap (BPF psock) integration hides a lot of latent bugs.\nBugs which may be more or less relevant for real users but they\nare definitely exploitable.\n\nWe could not find anyone actively using this integration so let's\nreject this config. Adding a TLS socket to a sockmap was already\nrejected by sk_psock_init() through the inet_csk_has_ulp() check.\nWe need to reject the attempts to configure the TLS keys (rather\nthan adding the ULP itself) because checking prior to the ULP\ninstallation is tricky without risking a race with sockmap getting\nadded in parallel (sockmap does not hold the socket lock).\n\nThis patch is a minimal rejection of the feature. Subsequent patch\nin the series will do a light dead code removal. Full cleanup would\nrequire a major rewrite of the Tx path, we don't need skmsg any more."
    }
  ],
  "lastModified": "2026-10-03T11:17:52.223",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}