[PATCH net v2 0/2] tls: fix plaintext sk_msg ring over-fill

chanyoung <[email protected]> Tue, 4 Aug 2026 14:28:34 +0900
Newsgroups gmane.linux.network
Message-ID <[email protected]>
An unprivileged user can oops the kernel by splicing into a kTLS socket
whose open record already has a full plaintext sk_msg ring.  Reproduced on
net (53658c6f3682) with a stock config, no KASAN.

Patch 2 oopses an unpatched kernel and passes with patch 1 applied.

v2:
  - fix the copy path so a full record is never left unpushed, rather than
    making tls_sw_sendmsg_splice() tolerate a full ring (Sabrina)
  - selftest: drop the comments, one splice instead of four, reuse a single
    pipe, compare the whole blob, sweep 16..44 fragments
v1: https://lore.kernel.org/netdev/[email protected]/

chanyoung (2):
  tls: don't leave a full plaintext sk_msg ring unpushed
  selftests: tls: add a test for splicing onto a full plaintext record

 net/tls/tls_sw.c                  | 14 ++++++++++++
 tools/testing/selftests/net/tls.c | 37 +++++++++++++++++++++++++++++++
 2 files changed, 51 insertions(+)

-- 
2.43.0