Review reviewCritical

CVE-2026-64046

Linux

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed...

CVSS
9.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.20
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 9.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed...

Affected product and versions

Product
Linux
Affected versions
>= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 49a5faaa471ddcd37b6893970c9916eb836e7c31, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 91359966e247c0244c66d50bbb8e74aefa4321c3, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 410351158dfef2d67fea6603680b3a6013c6ed9d, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < acdc12b71c9aa4be5dcd2c8062753c6d2033e235, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < 929b1548e63ac72e104c07d8ee8cbbeeba2fa89a, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < af855f4c966afafef74faf8390c7b86568c0d46d, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < b9c015ef1a7bf1e8dc67f21c6381f36deb2c3a36, >= 9aaaa56845a06aeabdd597cbe19492dc01f281ec < ff26a0e8377dec07e4a7230db7675bed1b9a6d03, >= d529d6c9f7e3aaeac13c4948f79799ccb825f29d, >= 5.4.14 < 5.5, >= 5.5
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available