PT-2026-106603 · Linux · Linux

CVE-2026-98274

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
net: psp: avoid conflicts with skb->decrypted and sk validate xmit skb()
PSP conflicts with TLS ULP in its usage of both skb->decrypted and sk->sk validate xmit skb().
Make PSP mutually exclusive with TLS ULP, the only other user of either of these. As other users of skb->decrypted come along, they can be added to sk has decrypt user(). It would make sense to also assert that sk->sk validate xmit skb() is also NULL in both of these setup paths for similar future proofing, but the PSP listener/sk clone() path is still broken and it could be seen as a regression to not allow rx assoc to run on a child of a listener socket with PSP tx assoc state.
Include all TCP ULPs in the sk has decrypt user() check, even though TLS is the only one that conflicts with PSP via the decrypted bit. This is intentional because PSP was not designed to be used with ULPs. It is best to close off surface area that may make bugs reachable, until someone wishes to design and test an actual user of PSP with ULPs.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98274

Produtos afetados

Linux