CVE-2026-64025
CVE CVE-2026-64025EUVD EUVD-2026-45598Published 2026-07-19T15:39:17.000ZLast changed 2026-08-05T12:38:19.000ZCVSS 9.8
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: bpf, skmsg: fix verdict sk_data_ready racing with ktls rx sk_psock_strp_data_ready() already checks tls_sw_has_ctx_rx() and defers to psock->saved_data_ready when a TLS RX context is present, avoiding a conflict with the TLS strparser's ownership of the receive queue (commit e91de6afa81c, "bpf: Fix running sk_skb program types with ktls"). sk_psock_verdict_data_ready() has no equivalent guard. When a socket is inserted into a sockmap (BPF_SK_SKB_VERDICT) before TLS RX is configured, tls_sw_strparser_arm() saves sk_psock_verdict_data_ready as rx_ctx->saved_data_ready. On data arrival: tls_data_ready -> tls_strp_data_ready -> tls_rx_msg_ready -> saved_data_ready() = sk_psock_verdict_data_ready() -> tcp_read_skb() drains sk_receive_queue via __skb_unlink() without calling tcp_eat_skb(), so copied_seq is not advanced. tls_strp_msg_load() then finds tcp_inq() >= full_len (stale), calls tcp_recv_skb() on the now-empty queue, hits WARN_ON_ONCE(!first), and returns with rx_ctx->strp.anchor.frag_list pointing at a psock-owned (potentially freed) skb. tls_decrypt_sg() subsequently walks that frag_list: use-after-free. Apply the same fix as sk_psock_strp_data_ready(): if a TLS RX context is present, call psock->saved_data_ready (sock_def_readable) to wake recv() waiters and return immediately, leaving the receive queue untouched. TLS retains sole ownership of the queue and decrypts the record normally through tls_sw_recvmsg().
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 0; ef5659280eb13e8ac31c296f58cfdfa1684ac06b <c9ea01768903ae47f210cd457af1dead6de7a9c3; patch: 7.0.11; patch: 6.12.92; ef5659280eb13e8ac31c296f58cfdfa1684ac06b <7c8cf21bc4efb4af18d6096db3f8bd06d622251c; patch: 6.18.34; patch: 7.1; ef5659280eb13e8ac31c296f58cfdfa1684ac06b <8a52139560f833c3975032e1f5762611e3a36d71; 5.10; ef5659280eb13e8ac31c296f58cfdfa1684ac06b <ddf8029623a1af20e984c040e89ff918158397ab; patch: 6.6.142; ef5659280eb13e8ac31c296f58cfdfa1684ac06b <1861d369efd62d67796563bf3e01fc22e5626f8b
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.