CVE-2026-80852: tls: device: fix out-of-bounds write in tls_append_frag()
In the Linux kernel, the following vulnerability has been resolved:
tls: device: fix out-of-bounds write in tlsappendfrag()
Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tlsdevice.c is otherwise only reachable on a machine with a NIC that implements the offload.
tlspushdata() only checks whether the open record still has room for another frag at the bottom of its loop, and the MSGMORE early break skips that check. The record survives to the next syscall with the frag count it already had, and tlsappendfrag() does not check either, so with TLSTXZEROCOPYRO every splice(SPLICEFMORE) of a byte or two adds a non-coalescing pipe page and numfrags walks off the end of tlsrecordinfo.frags[MAXSKBFRAGS]. Once the record is pushed, tlspushrecord() runs the same index over sgtxdata[MAXSKBFRAGS] and the sgsetpage() writes land on the destructwork that follows it, which the workqueue then calls.
The byte limit is fine because copy drops to 0 and the loop falls through to the same check; the frag count has no such feedback.
Push the record rather than keep a full one open, which is what a plain TCP socket does - tcpsendmsglocked() uses tcpmarkpush() and newsegment in both the copy and the MSGSPLICEPAGES paths, and tlssw already sets fullrecord when the skmsg ring fills up, MSGMORE or not.
BUG: KASAN: slab-out-of-bounds in tlsappendfrag ( net/tls/tlsdevice.c:269) Write of size 8 at addr ffff8881104d1530 by task tlsoob/450
CPU: 2 UID: 0 PID: 450 Comm: tlsoob Not tainted 7.2.0-rc7+ #329 PREEMPT Call Trace: <TASK> dumpstacklvl (lib/dumpstack.c:94 lib/dumpstack.c:120) printreport (mm/kasan/report.c:378 mm/kasan/report.c:482) kasanreport (mm/kasan/report.c:595) tlsappendfrag (net/tls/tlsdevice.c:269) tlspushdata (net/tls/tlsdevice.c:518) tlsdevicesendmsg (net/tls/tlsdevice.c:583) inetsendmsg (net/ipv4/afinet.c:865) socksendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813) splicetosocket (fs/splice.c:884) dosplice (fs/splice.c:936 fs/splice.c:1349) dosplice (fs/splice.c:1431) x64syssplice (fs/splice.c:1634 fs/splice.c:1616) dosyscall64 (arch/x86/entry/syscall64.c:63 arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) </TASK>
and, once the record is pushed:
UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:300:24 index 18 is out of range for type 'skbfragt [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:301:41 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:302:39 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:307:38 index 26 is out of range for type 'scatterlist [17]'
kernel tried to execute NX-protected page - exploit attempt? (uid: 0) BUG: unable to handle page fault for address: ffffea000411a680 #PF: supervisor instruction fetch in kernel mode #PF: errorcode(0x0011) - permissions violation Oops: Oops: 0011 [#1] SMP KASAN PTI Workqueue: ktlsdevicedestruct 0xffffea000411a680 RIP: 0010:0xffffea000411a680 Call Trace: <TASK> workerthread (kernel/workqueue.c:3405 kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) retfromfork (arch/x86/kernel/process.c:158) retfromforkasm (arch/x86/entry/entry64.S:245) </TASK>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 7.2.0-rc7+Patch tls: device: fix out-of-bounds write in tls_append_frag() - Configuration
Update/patch the Linux kernel so that tls_append_frag() performs the missing bounds checking for sg_tx_data[MAX_SKB_FRAGS]/tls_record_info.frags[MAX_SKB_FRAGS] (fix for out-of-bounds write in net/tls/tls_device.c around tls_append_frag()/tls_push_record()).
Linux kernel KTLS device (net/tls/tls_device.c) TLS device fix for tls_append_frag out-of-bounds write = Apply vendor/kernel patch containing the fix referenced as "tls: device: fix out-of-bounds write in tls_append_frag()"
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The affected code path is otherwise reachable only on machines with a NIC that implements TLS offload. The issue was reproduced using netdevsim TLS offload emulation.
What conditions are needed to trigger the out-of-bounds write?
An attacker or local workload needs to use TLS_TX_ZEROCOPY_RO and repeatedly splice one or two bytes with SPLICE_F_MORE. Each splice can add a non-coalescing pipe page, allowing the record fragment count to exceed MAX_SKB_FRAGS.
What can be done if the relevant kernel update cannot be applied immediately?
Avoid keeping a full TLS record open across calls in this path. Pushing the record instead prevents additional fragments from being appended after it is full.