Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99542.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-99542
Upstream
Published
2026-09-04T16:18:14Z
Modified
2026-09-05T14:17:03.899262150Z
Summary
CVE-2026-80852 affecting package kernel 6.6.150.1-1
Details

In the Linux kernel, the following vulnerability has been resolved:

tls: device: fix out-of-bounds write in tlsappendfrag()

Found with syzkaller and a local syzbot instance running on top of a netdevsim TLS offload emulation; tls_device.c is otherwise only reachable on a machine with a NIC that implements the offload.

tlspushdata() only checks whether the open record still has room for another frag at the bottom of its loop, and the MSGMORE early break skips that check. The record survives to the next syscall with the frag count it already had, and tlsappendfrag() does not check either, so with TLSTXZEROCOPYRO every splice(SPLICEFMORE) of a byte or two adds a non-coalescing pipe page and numfrags walks off the end of tlsrecordinfo.frags[MAXSKBFRAGS]. Once the record is pushed, tlspushrecord() runs the same index over sgtxdata[MAXSKBFRAGS] and the sgsetpage() writes land on the destructwork that follows it, which the workqueue then calls.

The byte limit is fine because copy drops to 0 and the loop falls through to the same check; the frag count has no such feedback.

Push the record rather than keep a full one open, which is what a plain TCP socket does - tcpsendmsglocked() uses tcpmarkpush() and newsegment in both the copy and the MSGSPLICEPAGES paths, and tlssw already sets fullrecord when the skmsg ring fills up, MSG_MORE or not.

BUG: KASAN: slab-out-of-bounds in tlsappendfrag ( net/tls/tlsdevice.c:269) Write of size 8 at addr ffff8881104d1530 by task tlsoob/450

CPU: 2 UID: 0 PID: 450 Comm: tlsoob Not tainted 7.2.0-rc7+ #329 PREEMPT Call Trace: <TASK> dumpstacklvl (lib/dumpstack.c:94 lib/dumpstack.c:120) printreport (mm/kasan/report.c:378 mm/kasan/report.c:482) kasanreport (mm/kasan/report.c:595) tlsappendfrag (net/tls/tlsdevice.c:269) tlspushdata (net/tls/tlsdevice.c:518) tlsdevicesendmsg (net/tls/tlsdevice.c:583) inetsendmsg (net/ipv4/afinet.c:865) socksendmsg (net/socket.c:775 net/socket.c:790 net/socket.c:813) splicetosocket (fs/splice.c:884) dosplice (fs/splice.c:936 fs/splice.c:1349) __do_splice (fs/splice.c:1431) _x64syssplice (fs/splice.c:1634 fs/splice.c:1616) dosyscall64 (arch/x86/entry/syscall64.c:63 arch/x86/entry/syscall64.c:94) entrySYSCALL64afterhwframe (arch/x86/entry/entry64.S:121) </TASK>

and, once the record is pushed:

UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:300:24 index 18 is out of range for type 'skbfragt [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:301:41 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:302:39 index 18 is out of range for type 'scatterlist [17]' UBSAN: array-index-out-of-bounds in net/tls/tlsdevice.c:307:38 index 26 is out of range for type 'scatterlist [17]'

kernel tried to execute NX-protected page - exploit attempt? (uid: 0) BUG: unable to handle page fault for address: ffffea000411a680 #PF: supervisor instruction fetch in kernel mode #PF: errorcode(0x0011) - permissions violation Oops: Oops: 0011 [#1] SMP KASAN PTI Workqueue: ktlsdevicedestruct 0xffffea000411a680 RIP: 0010:0xffffea000411a680 Call Trace: <TASK> workerthread (kernel/workqueue.c:3405 kernel/workqueue.c:3486) kthread (kernel/kthread.c:436) retfromfork (arch/x86/kernel/process.c:158) retfromforkasm (arch/x86/entry/entry64.S:245) </TASK>

References

Affected packages

Azure Linux:3 / kernel

Package

Name
kernel
Purl
pkg:rpm/azure-linux/kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.6.150.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-99542.json"