Improper Check for Unusual or Exceptional Conditions in Linux kernel - CVE-2026-80904
Published: September 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass TLS record authentication.
The vulnerability exists due to improper handling of cryptographic decryption errors in tls_sw_splice_read() when reading TLS records through splice. A remote attacker can cause a TLS record that failed authentication to be delivered through splice to bypass TLS record authentication.
Affected software
How to mitigate CVE-2026-80904
External References
- https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8
- https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861
- https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a
- https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647
- https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d
- https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b