TCP/IP Stack Vulnerability in Linux Kernel
CVE-2026-80904
What is CVE-2026-80904?
A vulnerability exists in the Linux kernel's TCP/IP stack related to improper handling of errors during asynchronous decryption operations in the TLS implementation. Specifically, the function tls_sw_splice_read() fails to check for errors in the async decryption context. This oversight enables a scenario where corrupted or unauthenticated records can continue to be delivered over a connection, bypassing safeguards present in related functions such as tls_sw_recvmsg() and tls_sw_read_sock(). As a result, this flaw could potentially lead to undetected transmission of erroneous packets, undermining the integrity and security of data exchanges.
Affected Version(s)
Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a
Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a < 06c2a53604fa1dc4820063828d7dadb3675b7af8
Linux f314bfee81b1bf8e01168177b2f65f24eb8da63a < 18ae1e95f20867106a28820c208a9cec99dda861