net: tls: prevent chain-after-chain in plain text SG

Summary

CVECVE-2026-64046
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-19 16:17:44 UTC
Updated2026-07-20 15:17:05 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed after the wrap: end start i v v v [ ]...[ ][ d ][ d ][ d ][ d ][rsv for wrap] Skip the wrapping in this case. TLS 1.3 can use the "wrapping slot" for it's chaining if end = 0. This avoids the chain-after-chain. Move the wrap chaining before marking END and chaining off content type, that feels like more logical ordering to me, but should not matter from functional perspective.

Risk And Classification

Primary CVSS: v3.1 9.8 CRITICAL from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.001760000 probability, percentile 0.073870000 (date 2026-07-20)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED9.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 49a5faaa471ddcd37b6893970c9916eb836e7c31 git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 91359966e247c0244c66d50bbb8e74aefa4321c3 git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 410351158dfef2d67fea6603680b3a6013c6ed9d git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec acdc12b71c9aa4be5dcd2c8062753c6d2033e235 git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 929b1548e63ac72e104c07d8ee8cbbeeba2fa89a git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec af855f4c966afafef74faf8390c7b86568c0d46d git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36 git Not specified
CNA Linux Linux affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec ff26a0e8377dec07e4a7230db7675bed1b9a6d03 git Not specified
CNA Linux Linux affected d529d6c9f7e3aaeac13c4948f79799ccb825f29d git Not specified
CNA Linux Linux affected 5.4.14 5.5 semver Not specified
CNA Linux Linux affected 5.5 Not specified
CNA Linux Linux unaffected 5.5 semver Not specified
CNA Linux Linux unaffected 5.10.258 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.209 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.175 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.142 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.92 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.34 6.18.* semver Not specified
CNA Linux Linux unaffected 7.0.11 7.0.* semver Not specified
CNA Linux Linux unaffected 7.1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/ff26a0e8377dec07e4a7230db7675bed1b9a6d03 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report