[PATCH net v2 0/2] tls: fix plaintext sk_msg ring over-fill
chanyoung <[email protected]> Tue, 4 Aug 2026 14:28:34 +0900
| Newsgroups | gmane.linux.network |
|---|---|
| Message-ID | <[email protected]> |
An unprivileged user can oops the kernel by splicing into a kTLS socket
whose open record already has a full plaintext sk_msg ring. Reproduced on
net (53658c6f3682) with a stock config, no KASAN.
Patch 2 oopses an unpatched kernel and passes with patch 1 applied.
v2:
- fix the copy path so a full record is never left unpushed, rather than
making tls_sw_sendmsg_splice() tolerate a full ring (Sabrina)
- selftest: drop the comments, one splice instead of four, reuse a single
pipe, compare the whole blob, sweep 16..44 fragments
v1: https://lore.kernel.org/netdev/[email protected]/
chanyoung (2):
tls: don't leave a full plaintext sk_msg ring unpushed
selftests: tls: add a test for splicing onto a full plaintext record
net/tls/tls_sw.c | 14 ++++++++++++
tools/testing/selftests/net/tls.c | 37 +++++++++++++++++++++++++++++++
2 files changed, 51 insertions(+)
--
2.43.0