net/tls: Fail tls_sw_splice_read() after a failed async decrypt
Published Sep 4, 2026
No CVSS score
EPSS 0.16%
Description
When an async decrypt fails, tls_decrypt_done() records the error in ctx->async_wait.err and calls tls_err_abort(), which stores it in sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read async_wait.err once they hold the reader lock and fail the call: a record that did not authenticate breaks the connection.
tls_sw_splice_read() has no such check, and sk_err does not stand in for one. tls_rx_rec_wait() tests sk_err only inside the loop it skips whenever a record is already parsed, and the first reader to reach sock_error() clears it, while async_wait.err persists. A splice therefore keeps delivering records on a connection that recvmsg() and read_sock() refuse to read.
Read async_wait.err in tls_sw_splice_read() as the other two readers do.
Affected products
-
Affected
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
- ≥ , <
-
Affected
- 5.19
Unaffected
- ≥ 0, < 5.19
- ≥ 6.1.184, ≤ 6.1.*
- ≥ 6.12.105, ≤ 6.12.*
- ≥ 6.18.46, ≤ 6.18.*
- ≥ 6.6.153, ≤ 6.6.*
- ≥ 7.1.10, ≤ 7.1.*
- 7.2
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71663 Advisory
- https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8
- https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861
- https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a
- https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647
- https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d
- https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data