Off-by-one in Linux kernel - CVE-2026-64047
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to an off-by-one error in tls_push_record() in the net/tls subsystem when chaining a wrapped sk_msg scatterlist ring. A local user can trigger the wrapped ring condition to cause a denial of service.
The issue occurs when the sk_msg scatterlist ring wraps with sg.end less than sg.start.
How to mitigate CVE-2026-64047
Sources
- https://git.kernel.org/stable/c/131ef12057d92b77b636321b7849c69222405a97
- https://git.kernel.org/stable/c/285943c6e7ca309bbea84b253745154241d9788a
- https://git.kernel.org/stable/c/2fb0dc7e0099686c4e9d2732745d8a31b18c3628
- https://git.kernel.org/stable/c/47110c3a9ac247b688657337f5981efcfcb240dc
- https://git.kernel.org/stable/c/66339b71f105e6f83e0da3b9583d95077534fe1d
- https://git.kernel.org/stable/c/73963a375885d5ccb7def39fd0b4f542e0f343dd
- https://git.kernel.org/stable/c/84158c2997159df4a0d70cd9c46774512d32a522
- https://git.kernel.org/stable/c/eca989eab4b2599dcb02f72140a7c08f08838520