Back

CRITICAL

tls: wait for pending async decryptions if tls_strp_msg_hold fails

Published Nov 12, 2025

Description

Async decryption calls tls_strp_msg_hold to create a clone of the input skb to hold references to the memory it uses. If we fail to allocate that clone, proceeding with async decryption can lead to various issues (UAF on the skb, writing into userspace memory after the recv() call has returned).

In this case, wait for all pending decryption requests.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Nov 12, 2025
Updated Aug 5, 2026
Reserved Apr 16, 2025
NVD
Status Deferred
Modified Jul 30, 2026
Red Hat
Severity Moderate
Public date Nov 12, 2025