CVE-2026-98274: net: psp: avoid conflicts with skb->decrypted and sk_validate_xmit_skb()

Published Oct 6, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: psp: avoid conflicts with skb->decrypted and skvalidatexmitskb()

PSP conflicts with TLS ULP in its usage of both skb->decrypted and sk->skvalidatexmitskb().

Make PSP mutually exclusive with TLS ULP, the only other user of either of these. As other users of skb->decrypted come along, they can be added to skhasdecryptuser(). It would make sense to also assert that sk->skvalidatexmitskb() is also NULL in both of these setup paths for similar future proofing, but the PSP listener/skclone() path is still broken and it could be seen as a regression to not allow rx assoc to run on a child of a listener socket with PSP tx assoc state.

Include all TCP ULPs in the skhasdecryptuser() check, even though TLS is the only one that conflicts with PSP via the decrypted bit. This is intentional because PSP was not designed to be used with ULPs. It is best to close off surface area that may make bugs reachable, until someone wishes to design and test an actual user of PSP with ULPs.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Do not use PSP with TCP ULPs, including TLS ULP; PSP was not designed to be used with ULPs.

    Linux kernel PSP and TCP ULPs PSP with TCP ULP = mutually exclusive

Event History

Oct 6, 2026
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
Description
Data Sourced
via NVD·09:18 AM
Description

Frequently Asked Questions

1

Which systems are exposed to this issue?

Linux kernel systems using PSP are the relevant population. The conflict is specifically with TCP ULPs, including TLS ULP; PSP was not designed to be used with ULPs.

2

What configuration causes the conflict?

The issue becomes reachable when PSP is used together with a TCP ULP on the same socket context. Both PSP and TLS ULP use skb->decrypted and sk->sk_validate_xmit_skb(), creating the conflict.

3

What mitigation is available if an update cannot be applied immediately?

Avoid combining PSP with any TCP ULP, particularly TLS ULP. The resolved change makes PSP mutually exclusive with TCP ULPs to prevent this unsupported combination.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203