Back

HIGH

tls: stop recv() if initial process_rx_list gave us non-DATA

Published Aug 22, 2025

Description

If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA

Just check the record type and jump to the end in case process_rx_list did some work.

Affected products

Remediation

Red Hat statement

The TLS recv path could mistakenly continue processing after process_rx_list() copied a non-DATA record, leading to merging of adjacent control records and inconsistent semantics. The fix makes recvmsg() stop immediately if the first processed record isn’t application data, preventing misinterpretation of TLS alerts/handshakes as data flow. Exploitation requires kTLS to be enabled and carefully crafted record sequencing, so the practical impact is limited to minor DoS of a TLS socket rather than confidentiality or integrity compromise.

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Aug 22, 2025
Updated Aug 5, 2026
Reserved Apr 16, 2025
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Aug 22, 2025
ENISA EUVD
Assigner Linux
Published Aug 22, 2025
Updated Aug 5, 2026
Exploited since n/a
EUVD-2024-55006