TCP/IP Stack Vulnerability in Linux Kernel
CVE-2026-80904

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80904?

A vulnerability exists in the Linux kernel's TCP/IP stack related to improper handling of errors during asynchronous decryption operations in the TLS implementation. Specifically, the function tls_sw_splice_read() fails to check for errors in the async decryption context. This oversight enables a scenario where corrupted or unauthenticated records can continue to be delivered over a connection, bypassing safeguards present in related functions such as tls_sw_recvmsg() and tls_sw_read_sock(). As a result, this flaw could potentially lead to undetected transmission of erroneous packets, undermining the integrity and security of data exchanges.

Affected Version(s)

Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a

Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a < 06c2a53604fa1dc4820063828d7dadb3675b7af8

Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a < 18ae1e95f20867106a28820c208a9cec99dda861

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.