{"api_version":"1","generated_at":"2026-07-24T18:52:43+00:00","cve":"CVE-2026-64046","urls":{"html":"https://cve.report/CVE-2026-64046","api":"https://cve.report/api/cve/CVE-2026-64046.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-64046","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-64046"},"summary":{"title":"net: tls: prevent chain-after-chain in plain text SG","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: prevent chain-after-chain in plain text SG\n\nSashiko points out that if end = 0 (start != 0) the current\ncode will create a chain link to content type right after\nthe wrap link:\n\n  This would create a chain where the wrap link points directly\n  to another chain link. The scatterlist API sg_next iterator\n  does not recursively resolve consecutive chain links.\n\nmeaning this is illegal input to crypto.\n\nThe wrapping link is unnecessary if end = 0. end is the entry after\nthe last one used so end = 0 means there's nothing pushed after\nthe wrap:\n\n   end         start            i\n    v            v              v\n  [   ]...[   ][ d ][ d ][ d ][ d ][rsv for wrap]\n\nSkip the wrapping in this case.\n\nTLS 1.3 can use the \"wrapping slot\" for it's chaining if end = 0.\nThis avoids the chain-after-chain.\n\nMove the wrap chaining before marking END and chaining off content\ntype, that feels like more logical ordering to me, but should not\nmatter from functional perspective.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-07-19 16:17:44","updated_at":"2026-07-20 15:17:05"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3","name":"https://git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a","name":"https://git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d","name":"https://git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d","name":"https://git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31","name":"https://git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235","name":"https://git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36","name":"https://git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ff26a0e8377dec07e4a7230db7675bed1b9a6d03","name":"https://git.kernel.org/stable/c/ff26a0e8377dec07e4a7230db7675bed1b9a6d03","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-64046","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64046","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 49a5faaa471ddcd37b6893970c9916eb836e7c31 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 91359966e247c0244c66d50bbb8e74aefa4321c3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 410351158dfef2d67fea6603680b3a6013c6ed9d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec acdc12b71c9aa4be5dcd2c8062753c6d2033e235 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec 929b1548e63ac72e104c07d8ee8cbbeeba2fa89a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec af855f4c966afafef74faf8390c7b86568c0d46d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 9aaaa56845a06aeabdd597cbe19492dc01f281ec ff26a0e8377dec07e4a7230db7675bed1b9a6d03 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d529d6c9f7e3aaeac13c4948f79799ccb825f29d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.4.14 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.5","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.5 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.258 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.209 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.175 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.142 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.92 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.34 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.0.11 7.0.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"64046","cve":"CVE-2026-64046","epss":"0.001760000","percentile":"0.073870000","score_date":"2026-07-20","updated_at":"2026-07-21 00:13:13"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"49a5faaa471ddcd37b6893970c9916eb836e7c31","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"91359966e247c0244c66d50bbb8e74aefa4321c3","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"410351158dfef2d67fea6603680b3a6013c6ed9d","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"acdc12b71c9aa4be5dcd2c8062753c6d2033e235","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"929b1548e63ac72e104c07d8ee8cbbeeba2fa89a","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"af855f4c966afafef74faf8390c7b86568c0d46d","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"lessThan":"ff26a0e8377dec07e4a7230db7675bed1b9a6d03","status":"affected","version":"9aaaa56845a06aeabdd597cbe19492dc01f281ec","versionType":"git"},{"status":"affected","version":"d529d6c9f7e3aaeac13c4948f79799ccb825f29d","versionType":"git"},{"lessThan":"5.5","status":"affected","version":"5.4.14","versionType":"semver"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/tls/tls_sw.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.5"},{"lessThan":"5.5","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.258","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.209","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.175","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.142","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.92","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.34","versionType":"semver"},{"lessThanOrEqual":"7.0.*","status":"unaffected","version":"7.0.11","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.258","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.209","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.175","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.142","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.92","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.34","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.0.11","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1","versionStartIncluding":"5.5","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.14","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: prevent chain-after-chain in plain text SG\n\nSashiko points out that if end = 0 (start != 0) the current\ncode will create a chain link to content type right after\nthe wrap link:\n\n  This would create a chain where the wrap link points directly\n  to another chain link. The scatterlist API sg_next iterator\n  does not recursively resolve consecutive chain links.\n\nmeaning this is illegal input to crypto.\n\nThe wrapping link is unnecessary if end = 0. end is the entry after\nthe last one used so end = 0 means there's nothing pushed after\nthe wrap:\n\n   end         start            i\n    v            v              v\n  [   ]...[   ][ d ][ d ][ d ][ d ][rsv for wrap]\n\nSkip the wrapping in this case.\n\nTLS 1.3 can use the \"wrapping slot\" for it's chaining if end = 0.\nThis avoids the chain-after-chain.\n\nMove the wrap chaining before marking END and chaining off content\ntype, that feels like more logical ordering to me, but should not\nmatter from functional perspective."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"providerMetadata":{"dateUpdated":"2026-07-20T13:42:46.777Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/49a5faaa471ddcd37b6893970c9916eb836e7c31"},{"url":"https://git.kernel.org/stable/c/91359966e247c0244c66d50bbb8e74aefa4321c3"},{"url":"https://git.kernel.org/stable/c/410351158dfef2d67fea6603680b3a6013c6ed9d"},{"url":"https://git.kernel.org/stable/c/acdc12b71c9aa4be5dcd2c8062753c6d2033e235"},{"url":"https://git.kernel.org/stable/c/929b1548e63ac72e104c07d8ee8cbbeeba2fa89a"},{"url":"https://git.kernel.org/stable/c/af855f4c966afafef74faf8390c7b86568c0d46d"},{"url":"https://git.kernel.org/stable/c/b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36"},{"url":"https://git.kernel.org/stable/c/ff26a0e8377dec07e4a7230db7675bed1b9a6d03"}],"title":"net: tls: prevent chain-after-chain in plain text SG","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-64046","datePublished":"2026-07-19T15:39:31.129Z","dateReserved":"2026-07-19T07:54:57.029Z","dateUpdated":"2026-07-20T13:42:46.777Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-07-19 16:17:44","lastModifiedDate":"2026-07-20 15:17:05","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"64046","Ordinal":"1","Title":"net: tls: prevent chain-after-chain in plain text SG","CVE":"CVE-2026-64046","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"64046","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: prevent chain-after-chain in plain text SG\n\nSashiko points out that if end = 0 (start != 0) the current\ncode will create a chain link to content type right after\nthe wrap link:\n\n  This would create a chain where the wrap link points directly\n  to another chain link. The scatterlist API sg_next iterator\n  does not recursively resolve consecutive chain links.\n\nmeaning this is illegal input to crypto.\n\nThe wrapping link is unnecessary if end = 0. end is the entry after\nthe last one used so end = 0 means there's nothing pushed after\nthe wrap:\n\n   end         start            i\n    v            v              v\n  [   ]...[   ][ d ][ d ][ d ][ d ][rsv for wrap]\n\nSkip the wrapping in this case.\n\nTLS 1.3 can use the \"wrapping slot\" for it's chaining if end = 0.\nThis avoids the chain-after-chain.\n\nMove the wrap chaining before marking END and chaining off content\ntype, that feels like more logical ordering to me, but should not\nmatter from functional perspective.","Type":"Description","Title":"net: tls: prevent chain-after-chain in plain text SG"}]}}}