Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2026-64025

bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
Back to all
CVE

CVE-2026-64025

bpf, skmsg: fix verdict sk_data_ready racing with ktls rx

In the Linux kernel, the following vulnerability has been resolved:

bpf, skmsg: fix verdict skdataready racing with ktls rx

skpsockstrpdataready() already checks tlsswhasctxrx() and

defers to psock->saveddataready when a TLS RX context is present,

avoiding a conflict with the TLS strparser's ownership of the receive

queue (commit e91de6afa81c, "bpf: Fix running sk_skb program types

with ktls").

skpsockverdictdataready() has no equivalent guard.  When a socket

is inserted into a sockmap (BPFSKSKB_VERDICT) before TLS RX is

configured, tlsswstrparserarm() saves skpsockverdictdata_ready

as rxctx->saveddata_ready.  On data arrival:

  tlsdataready -> tlsstrpdataready -> tlsrxmsgready

    -> saveddataready() = skpsockverdictdataready()

      -> tcpreadskb() drains skreceivequeue via _skbunlink()

         without calling tcpeatskb(), so copied_seq is not advanced.

tlsstrpmsgload() then finds tcpinq() >= full_len (stale), calls

tcprecvskb() on the now-empty queue, hits WARNONONCE(!first), and

returns with rxctx->strp.anchor.fraglist pointing at a psock-owned

(potentially freed) skb.  tlsdecryptsg() subsequently walks that

frag_list: use-after-free.

Apply the same fix as skpsockstrpdataready(): if a TLS RX context

is present, call psock->saveddataready (sockdefreadable) to wake

recv() waiters and return immediately, leaving the receive queue

untouched.  TLS retains sole ownership of the queue and decrypts the

record normally through tlsswrecvmsg().

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
9.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://git.kernel.org/stable/c/1861d369efd62d67796563bf3e01fc22e5626f8b, https://git.kernel.org/stable/c/7c8cf21bc4efb4af18d6096db3f8bd06d622251c, https://git.kernel.org/stable/c/8a52139560f833c3975032e1f5762611e3a36d71, https://git.kernel.org/stable/c/c9ea01768903ae47f210cd457af1dead6de7a9c3, https://git.kernel.org/stable/c/ddf8029623a1af20e984c040e89ff918158397ab, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64025.json, https://nvd.nist.gov/vuln/detail/CVE-2026-64025, https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Severity

9.8

CVSS Score
0
10

Basic Information

Base CVSS
9.8
EPSS Probability
0.00444%
EPSS Percentile
0.37166%
Introduced Version
ef5659280eb13e8ac31c296f58cfdfa1684ac06b,5.10.0,6.7.0,6.13.0,6.19.0,0
Fix Available
ddf8029623a1af20e984c040e89ff918158397ab,6.6.142,6.12.92,6.18.34,7.0.11,6.12.94-1,7.0.0-28.28~24.04.1,7.0.0-1016.16~24.04.1,7.0.0-28.28.1~24.04.3,1:6.18.35-68.127.amzn2023,1:1.0-0.amzn2023,1:6.12.92-122.166.amzn2023

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading