{"api_version":"1","generated_at":"2026-10-01T11:59:29+00:00","cve":"CVE-2026-93824","urls":{"html":"https://cve.report/CVE-2026-93824","api":"https://cve.report/api/cve/CVE-2026-93824.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93824","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93824"},"summary":{"title":"tls: reject the combination of TLS and sockmap","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: reject the combination of TLS and sockmap\n\nTLS and sockmap (BPF psock) integration hides a lot of latent bugs.\nBugs which may be more or less relevant for real users but they\nare definitely exploitable.\n\nWe could not find anyone actively using this integration so let's\nreject this config. Adding a TLS socket to a sockmap was already\nrejected by sk_psock_init() through the inet_csk_has_ulp() check.\nWe need to reject the attempts to configure the TLS keys (rather\nthan adding the ULP itself) because checking prior to the ULP\ninstallation is tricky without risking a race with sockmap getting\nadded in parallel (sockmap does not hold the socket lock).\n\nThis patch is a minimal rejection of the feature. Subsequent patch\nin the series will do a light dead code removal. Full cleanup would\nrequire a major rewrite of the Tx path, we don't need skmsg any more.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-24 17:17:16","updated_at":"2026-09-25 13:17:23"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/a08e780b6cc1153cbff8be55de9ec9da809e344f","name":"https://git.kernel.org/stable/c/a08e780b6cc1153cbff8be55de9ec9da809e344f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/460e6486617c17dd19abe8f3fc67d9a6fa25f8ca","name":"https://git.kernel.org/stable/c/460e6486617c17dd19abe8f3fc67d9a6fa25f8ca","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c3d4d537337f69e405a36fa561e7292ee4148bf7","name":"https://git.kernel.org/stable/c/c3d4d537337f69e405a36fa561e7292ee4148bf7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93824","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93824","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d3b18ad31f93d0b6bae105c679018a1ba7daa9ca c3d4d537337f69e405a36fa561e7292ee4148bf7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d3b18ad31f93d0b6bae105c679018a1ba7daa9ca a08e780b6cc1153cbff8be55de9ec9da809e344f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected d3b18ad31f93d0b6bae105c679018a1ba7daa9ca 460e6486617c17dd19abe8f3fc67d9a6fa25f8ca git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.20","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.20 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.111 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.53 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"93824","cve":"CVE-2026-93824","epss":"0.001660000","percentile":"0.052150000","score_date":"2026-09-27","updated_at":"2026-09-28 00:02:24"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["net/tls/tls_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"c3d4d537337f69e405a36fa561e7292ee4148bf7","status":"affected","version":"d3b18ad31f93d0b6bae105c679018a1ba7daa9ca","versionType":"git"},{"lessThan":"a08e780b6cc1153cbff8be55de9ec9da809e344f","status":"affected","version":"d3b18ad31f93d0b6bae105c679018a1ba7daa9ca","versionType":"git"},{"lessThan":"460e6486617c17dd19abe8f3fc67d9a6fa25f8ca","status":"affected","version":"d3b18ad31f93d0b6bae105c679018a1ba7daa9ca","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["net/tls/tls_main.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.20"},{"lessThan":"4.20","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.111","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.53","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.111","versionStartIncluding":"4.20","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.53","versionStartIncluding":"4.20","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"4.20","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: reject the combination of TLS and sockmap\n\nTLS and sockmap (BPF psock) integration hides a lot of latent bugs.\nBugs which may be more or less relevant for real users but they\nare definitely exploitable.\n\nWe could not find anyone actively using this integration so let's\nreject this config. Adding a TLS socket to a sockmap was already\nrejected by sk_psock_init() through the inet_csk_has_ulp() check.\nWe need to reject the attempts to configure the TLS keys (rather\nthan adding the ULP itself) because checking prior to the ULP\ninstallation is tricky without risking a race with sockmap getting\nadded in parallel (sockmap does not hold the socket lock).\n\nThis patch is a minimal rejection of the feature. Subsequent patch\nin the series will do a light dead code removal. Full cleanup would\nrequire a major rewrite of the Tx path, we don't need skmsg any more."}],"providerMetadata":{"dateUpdated":"2026-09-25T12:43:33.584Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/c3d4d537337f69e405a36fa561e7292ee4148bf7"},{"url":"https://git.kernel.org/stable/c/a08e780b6cc1153cbff8be55de9ec9da809e344f"},{"url":"https://git.kernel.org/stable/c/460e6486617c17dd19abe8f3fc67d9a6fa25f8ca"}],"title":"tls: reject the combination of TLS and sockmap","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93824","datePublished":"2026-09-24T16:03:02.783Z","dateReserved":"2026-09-18T17:59:28.792Z","dateUpdated":"2026-09-25T12:43:33.584Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-24 17:17:16","lastModifiedDate":"2026-09-25 13:17:23","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93824","Ordinal":"1","Title":"tls: reject the combination of TLS and sockmap","CVE":"CVE-2026-93824","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93824","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ntls: reject the combination of TLS and sockmap\n\nTLS and sockmap (BPF psock) integration hides a lot of latent bugs.\nBugs which may be more or less relevant for real users but they\nare definitely exploitable.\n\nWe could not find anyone actively using this integration so let's\nreject this config. Adding a TLS socket to a sockmap was already\nrejected by sk_psock_init() through the inet_csk_has_ulp() check.\nWe need to reject the attempts to configure the TLS keys (rather\nthan adding the ULP itself) because checking prior to the ULP\ninstallation is tricky without risking a race with sockmap getting\nadded in parallel (sockmap does not hold the socket lock).\n\nThis patch is a minimal rejection of the feature. Subsequent patch\nin the series will do a light dead code removal. Full cleanup would\nrequire a major rewrite of the Tx path, we don't need skmsg any more.","Type":"Description","Title":"tls: reject the combination of TLS and sockmap"}]}}}