Affected Versions : Linux kernel 6.0 through 6.1.148; 6.2 through 6.6.102; 6.7 through 6.12.43; 6.13 through 6.16.3; 6.17-rc1 and 6.17-rc2
CVSS3.1 : 7.1 (High) — CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS3.1 Scoring System
Base Score: 7.1 (High) Vector String: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
The Linux kernel’s net/tls subsystem implements kernel-side TLS record processing. When a socket is configured with TCP_ULP set to "tls" , receive-path processing is handled by tls_sw_recvmsg , which decrypts incoming TLS records and delivers plaintext to the caller. The stream parser ( strp ) maintains an anchor SKB ( strp->anchor ) to track in-progress records during zero-copy decryption.
In tls_sw_recvmsg , when copied == 0 the function loops to receive additional packets. A zero-length decrypted TLS record can produce this condition, causing the loop to continue:
On the iteration, if the new record’s content type differs from the previously established control value, tls_record_content_type returns 0 :
When tls_record_content_type returns 0 or a negative value, the error path queues darg.skb (which is strp->anchor ) into ctx->rx_list :
The critical issue is that when darg.zc == 1 (zero-copy mode is active), queuing darg.skb into rx_list is forbidden. Doing so corrupts strp->anchor->frag_list and the anchor’s reference count, leading to a use-after-free when the socket is subsequently closed and tls_sw_release_resources_rx walks the freed memory.
KASAN confirms the UAF at kfree_skb_list_reason , triggered during tls_sw_release_resources_rx → skb_release_data on socket close. The SKB was originally allocated by tcp_sendmsg_locked and freed by tls_strp_msg_done inside tls_sw_recvmsg before the erroneous re-queue.
The trigger sequence is:
Send a TLS Application Data record (type 0x17 , “Hello world”).
Send a zero-length TLS Handshake record (type 0x16 , empty plaintext).
Partially consume the first record with read(conn, buf, 0x100) — leaving copied == 0 on the call.
Send a second Application Data record (type 0x17 ).
Call recvmsg — the content-type mismatch between the handshake record and the subsequent application data triggers the buggy rx_list enqueue with darg.zc == 1 .
Close the socket — UAF fires in tls_sw_release_resources_rx .
Proof-Of-Concept Crash log
Run poc under Linux 6.12.41
Python script to generate tls_record with content type [0x17, 0x16, 0x17], the second tls_record have zero length.
Billy Jheng Bing-Jhong and Muhammad Alifa Ramdhan of STAR Labs SG Pte. Ltd.
2025-08-12 — Vulnerability reported to Linux kernel security team
2025-09-05 — Patch released; CVE-2025-39682 published
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
